First published: Wed Jul 13 2022(Updated: )
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause unauthorized firmware image loading when unsigned images are added to the firmware image path. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Opc Ua Module For M580 Firmware | <=1.10 | |
Schneider-electric Opc Ua Module For M580 | ||
Schneider-electric X80 Advanced Rtu Module Firmware | >=2.01 | |
Schneider-electric X80 Advanced Rtu Module |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34762 has a CVSS score that indicates it poses a high risk due to potential unauthorized firmware loading.
To fix CVE-2022-34762, update the affected Schneider Electric products to the latest firmware version that mitigates the vulnerability.
CVE-2022-34762 affects the Schneider Electric X80 Advanced RTU Communication Module firmware versions starting from 2.01.
CVE-2022-34762 is a Path Traversal vulnerability that can lead to unauthorized actions such as loading unsigned firmware images.
While specific workarounds are not detailed, temporarily limiting access to firmware loading functions may reduce risk until a patch is applied.