CVE-2022-45789
A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.46%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session. Affected Products: EcoStruxure Control Expert (All Versions), EcoStruxure Process Expert (All Versions), Modicon M340 CPU - part numbers BMXP34* (All Versions), Modicon M580 CPU - part numbers BMEP* and BMEH* (All Versions), Modicon M580 CPU Safety - part numbers BMEP58*S and BMEH58*S (All Versions)
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.46% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-294
- Affected
- schneider-electric/ecostruxure control expert · schneider-electric/ecostruxure process expert · schneider-electric/modicon m340 bmxp341000 firmware · schneider-electric/modicon m340 bmxp342000 firmware · schneider-electric/modicon m340 bmxp342010 firmware · schneider-electric/modicon m340 bmxp3420102 firmware · schneider-electric/modicon m340 bmxp342020 firmware · schneider-electric/modicon m340 bmxp342020h firmware · schneider-electric/modicon m340 bmxp342030 firmware · schneider-electric/modicon m340 bmxp3420302 firmware · schneider-electric/modicon m340 bmxp3420302h firmware · schneider-electric/modicon m340 bmxp342030h firmware · schneider-electric/modicon m580 bmep581020 firmware · schneider-electric/modicon m580 bmep581020h firmware · schneider-electric/modicon m580 bmep582020 firmware · schneider-electric/modicon m580 bmep582020h firmware · schneider-electric/modicon m580 bmep582040 firmware · schneider-electric/modicon m580 bmep582040h firmware · schneider-electric/modicon m580 bmep582040s firmware · schneider-electric/modicon m580 bmep583020 firmware · +17 more
- Source
- cybersecurity@se.com
References
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-010-06&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-010-06_Modicon_Controllers_Security_Notification.pdfPatch, Vendor Advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-010-06&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-010-06_Modicon_Controllers_Security_Notification.pdfPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.