CVE-2022-22724
A CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service on ports 80 (HTTP) and 502 (Modbus), when sending a large number of TCP RST or FIN packets to any open TCP port of the PLC.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.93%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service on ports 80 (HTTP) and 502 (Modbus), when sending a large number of TCP RST or FIN packets to any open TCP port of the PLC. Affected Product: Modicon M340 CPUs: BMXP34 (All Versions)
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.93% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Affected
- schneider-electric/modicon m340 bmxp341000 firmware · schneider-electric/modicon m340 bmxp342000 firmware · schneider-electric/modicon m340 bmxp342010 firmware · schneider-electric/modicon m340 bmxp3420102 firmware · schneider-electric/modicon m340 bmxp342030 firmware · schneider-electric/modicon m340 bmxp3420302 firmware
- Source
- cybersecurity@se.com
References
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-011-01Mitigation, Patch, Vendor Advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-011-01Mitigation, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.