First published: Tue Jan 31 2023(Updated: )
A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session. Affected Products: EcoStruxure Control Expert (All Versions), EcoStruxure Process Expert (All Versions), Modicon M340 CPU - part numbers BMXP34* (All Versions), Modicon M580 CPU - part numbers BMEP* and BMEH* (All Versions), Modicon M580 CPU Safety - part numbers BMEP58*S and BMEH58*S (All Versions)
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
EcoStruxure Control Expert | ||
Schneider Electric EcoStruxure Process Expert | <=2020 | |
Schneider Electric Modicon M340 BMXP341000 Firmware | ||
Schneider Electric Modicon M340 BMXP341000 | ||
Schneider Electric Modicon M340 BMXP342000 Firmware | ||
Schneider Electric Modicon M340 BMXP342000 Firmware | ||
Schneider Electric Modicon M340 BMXP342010 Firmware | ||
Schneider Electric Modicon M340 BMXP342010 Firmware | ||
Schneider Electric Modicon M340 BMXP3420102 Firmware | ||
Schneider Electric Modicon M340 BMXP3420102 | ||
Schneider Electric Modicon M340 BMXP342020 Firmware | ||
Schneider Electric Modicon M340 BMXP342020 | ||
Schneider Electric Modicon M340 BMXP342020H Firmware | ||
Schneider Electric Modicon M340 BMXP342020H | ||
Schneider Electric Modicon M340 BMXP342030 Firmware | ||
Schneider Electric Modicon M340 BMXP342030H | ||
Schneider Electric Modicon M340 BMXP3420302 Firmware | ||
Schneider Electric Modicon M340 BMXP3420302 Firmware | ||
Schneider Electric Modicon M340 BMXP3420302H Firmware | ||
Schneider Electric Modicon M340 BMXP3420302H Firmware | ||
Schneider Electric Modicon M340 BMXP342030H Firmware | ||
Schneider Electric Modicon M340 BMXP342030H | ||
Modicon M580 | ||
Schneider Electric Modicon M580 BMEP581020 | ||
schneider-electric Modicon M580 BMEP581020 firmware | ||
schneider-electric Modicon M580 BMEP581020H firmware | ||
Schneider Electric Modicon M580 BMEP582020 Firmware | ||
Modicon M580 | ||
Schneider Electric Modicon M580 Firmware | ||
Modicon M580 | ||
Schneider Electric Modicon M580 BMEP582040 Firmware | ||
schneider-electric Modicon M580 | ||
schneider-electric Modicon M580 bmep582040h firmware | ||
schneider-electric Modicon M580 | ||
Schneider Electric Modicon M580 BMEP582040 Firmware | ||
Schneider Electric Modicon M580 BMEP582040S | ||
Schneider Electric Modicon M580 BMEP583020 Firmware | ||
Schneider Electric Modicon M580 BMEP583020 | ||
Schneider Electric Modicon M580 BMEP583040 Firmware | ||
Schneider Electric Modicon M580 BMEP583040 | ||
Schneider Electric Modicon M580 BMEP584020 Firmware | ||
Schneider Electric Modicon M580 BMEP584020 Firmware | ||
Schneider Electric Modicon M580 BMEP584040 Firmware | ||
Schneider Electric Modicon M580 BMEP584040 Firmware | ||
Schneider Electric Modicon M580 BMEP584040S Firmware | ||
Schneider Electric Modicon M580 BMEP584040S Firmware | ||
schneider-electric Modicon M580 BMEP585040C Firmware | ||
schneider-electric Modicon M580 BMEP585040C Firmware | ||
Schneider Electric Modicon M580 BMEP585040C Firmware | ||
schneider-electric Modicon M580 BMEP585040C Firmware | ||
schneider-electric Modicon M580 bmep586040c firmware | ||
schneider-electric modicon m580 bmep586040 firmware | ||
Schneider Electric Modicon M580 BMEP585040C Firmware | ||
schneider-electric Modicon M580 bmep586040c firmware | ||
Schneider Electric Modicon M580 BMEH582040 Firmware | ||
schneider-electric Modicon M580 | ||
Schneider Electric Modicon M580 Firmware | ||
Modicon M580 | ||
Schneider Electric Modicon M580 Firmware | ||
schneider-electric Modicon M580 | ||
Schneider Electric Modicon M580 BMEH584040 Firmware | ||
schneider-electric Modicon M580 bmeh584040c | ||
Schneider Electric Modicon M580 Firmware | ||
schneider-electric Modicon M580 bmeh584040c firmware | ||
Schneider Electric Modicon M580 BMEH584040S Firmware | ||
Schneider Electric Modicon M580 BMEH584040S Firmware | ||
Schneider Electric Modicon M580 | ||
Schneider Electric Modicon M580 | ||
Schneider Electric Modicon M580 Firmware | ||
Schneider Electric Modicon M580 | ||
Schneider Electric Modicon M580 Firmware | ||
Schneider Electric Modicon M580 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-45789 has a moderate severity rating due to its risk of unauthorized Modbus function execution.
To fix CVE-2022-45789, update affected products such as EcoStruxure Control Expert and EcoStruxure Process Expert to the latest security patches.
CVE-2022-45789 affects Schneider Electric products, including EcoStruxure Control Expert and EcoStruxure Process Expert across all versions.
CVE-2022-45789 is categorized as an Authentication Bypass by Capture-replay vulnerability.
CVE-2022-45789 can result in execution of unauthorized commands on the controller, potentially compromising system integrity.