First published: Tue Nov 22 2022(Updated: )
A CWE-191: Integer Underflow (Wrap or Wraparound) vulnerability exists that could cause a denial of service of the controller due to memory access violations when using the Modbus TCP protocol. Affected products: Modicon M340 CPU (part numbers BMXP34*)(V3.40 and prior), Modicon M580 CPU (part numbers BMEP* and BMEH*)(V3.22 and prior), Legacy Modicon Quantum/Premium(All Versions), Modicon Momentum MDI (171CBU*)(All Versions), Modicon MC80 (BMKC80)(V1.7 and prior)
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric Modicon M340 Firmware | <3.50 | |
Modicon M340 | ||
Schneider Electric Modicon M340 BMX P34-2030 Firmware | <3.50 | |
Schneider Electric Modicon M340 | ||
Schneider Electric Modicon M580 BMEH582040 Firmware | <4.01 | |
schneider-electric Modicon M580 | ||
Schneider Electric Modicon M580 Firmware | <4.01 | |
Modicon M580 | ||
Schneider Electric Modicon M580 Firmware | <4.01 | |
schneider-electric Modicon M580 | ||
Schneider Electric Modicon M580 BMEH584040 Firmware | <4.01 | |
schneider-electric Modicon M580 bmeh584040c | ||
Schneider Electric Modicon M580 Firmware | <4.01 | |
schneider-electric Modicon M580 bmeh584040c firmware | ||
Schneider Electric Modicon M580 BMEH584040S Firmware | <4.01 | |
Schneider Electric Modicon M580 BMEH584040S Firmware | ||
Schneider Electric Modicon M580 | <4.01 | |
Schneider Electric Modicon M580 | ||
Schneider Electric Modicon M580 Firmware | <4.01 | |
Schneider Electric Modicon M580 | ||
Schneider Electric Modicon M580 Firmware | <4.01 | |
Schneider Electric Modicon M580 | ||
Modicon M580 | <4.01 | |
Schneider Electric Modicon M580 BMEP581020 | ||
schneider-electric Modicon M580 BMEP581020 firmware | <4.01 | |
schneider-electric Modicon M580 BMEP581020H firmware | ||
Schneider Electric Modicon M580 BMEP582020 Firmware | <4.01 | |
Modicon M580 | ||
Schneider Electric Modicon M580 Firmware | <4.01 | |
Modicon M580 | ||
Schneider Electric Modicon M580 BMEP582040 Firmware | <4.01 | |
schneider-electric Modicon M580 | ||
schneider-electric Modicon M580 bmep582040h firmware | <4.01 | |
schneider-electric Modicon M580 | ||
Schneider Electric Modicon M580 BMEP582040 Firmware | <4.01 | |
Schneider Electric Modicon M580 BMEP582040S | ||
Schneider Electric Modicon M580 BMEP583020 Firmware | <4.01 | |
Schneider Electric Modicon M580 BMEP583020 | ||
Schneider Electric Modicon M580 BMEP583040 Firmware | <4.01 | |
Schneider Electric Modicon M580 BMEP583040 | ||
Schneider Electric Modicon M580 BMEP584020 Firmware | <4.01 | |
Schneider Electric Modicon M580 BMEP584020 Firmware | ||
Schneider Electric Modicon M580 BMEP584040 Firmware | <4.01 | |
Schneider Electric Modicon M580 BMEP584040 Firmware | ||
Schneider Electric Modicon M580 BMEP584040S Firmware | <4.01 | |
Schneider Electric Modicon M580 BMEP584040S Firmware | ||
schneider-electric Modicon M580 BMEP585040C Firmware | <4.01 | |
schneider-electric Modicon M580 BMEP585040C Firmware | ||
Schneider Electric Modicon M580 BMEP585040C Firmware | <4.01 | |
schneider-electric Modicon M580 BMEP585040C Firmware | ||
schneider-electric Modicon M580 bmep586040c firmware | <4.01 | |
schneider-electric modicon m580 bmep586040 firmware | ||
Schneider Electric Modicon M580 BMEP585040C Firmware | <4.01 | |
schneider-electric Modicon M580 bmep586040c firmware | ||
Schneider Electric Modicon MC80 BMKC8020301 | <1.8 | |
schneider-electric modicon mc80 bmkc8020301 firmware | ||
Modicon MC80 Firmware | <1.8 | |
Modicon MC80 Firmware | ||
Modicon MC80 Firmware | <1.8 | |
Schneider Electric Modicon MC80 | ||
Schneider Electric Modicon Momentum 171CBU78090 | ||
Schneider Electric Modicon Momentum 171CBU78090 | ||
Schneider Electric Modicon Momentum 171CBU98090 | ||
Schneider Electric Modicon Momentum 171CBU98090 | ||
Schneider Electric Modicon Momentum 171CBU98091 Firmware | ||
Schneider Electric Modicon Momentum 171CBU98091 Firmware | ||
schneider-electric Modicon Premium TSXP57 1634m | ||
schneider-electric Modicon Premium TSXP57 1634m firmware | ||
schneider-electric Modicon Premium firmware | ||
Schneider Electric Modicon Premium | ||
schneider-electric Modicon Premium firmware | ||
schneider-electric Modicon Premium TSXP57 2834m firmware | ||
schneider-electric Modicon Premium firmware | ||
schneider-electric Modicon Premium TSXP57 454m firmware | ||
schneider-electric Modicon Premium TSXP57 4634m | ||
schneider-electric Modicon Premium TSXP57 4634m firmware | ||
schneider-electric Modicon Premium firmware | ||
schneider-electric Modicon Premium TSXP57 554m firmware | ||
schneider-electric Modicon Premium TSXP57 5634m | ||
schneider-electric Modicon Premium TSXP57 5634m firmware | ||
schneider-electric Modicon Premium firmware | ||
Schneider Electric Modicon Premium | ||
Schneider Electric Modicon Quantum Firmware | ||
schneider-electric Modicon Quantum 140cpu65150 firmware | ||
Schneider Electric Modicon Quantum 140CPU65160C Firmware | ||
schneider-electric Modicon Quantum 140cpu65150c firmware | ||
schneider-electric Modicon Quantum 140cpu65160 firmware | ||
schneider-electric Modicon Quantum 140cpu65160c | ||
schneider-electric Modicon Quantum 140cpu65160c | ||
Schneider Electric Modicon Quantum 140CPU65160C Firmware | ||
Modicon Quantum 140noc78100 | ||
Modicon Quantum 140noc78100 | ||
Schneider Electric Modicon Quantum Firmware | ||
Schneider-electric Quantum Ethernet Module 140noe77101 | ||
schneider-electric Modicon Quantum 140noe77111 firmware | ||
Modicon Quantum 140NOE77111 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-37301 is considered a high-severity vulnerability due to its potential to cause denial of service through memory access violations.
To fix CVE-2022-37301, update your Schneider Electric Modicon M340 CPU or Modicon M580 CPU firmware to version 3.50 or later, respectively.
CVE-2022-37301 affects Schneider Electric Modicon M340 CPUs with firmware V3.40 and prior, as well as Modicon M580 CPUs with firmware up to V4.01.
CVE-2022-37301 is classified as an Integer Underflow vulnerability, specifically associated with the Modbus TCP protocol.
Exploitation of CVE-2022-37301 can lead to denial of service conditions affecting the control system.