Improper Condition Check in Triconex Model 3009 MP on Tricon V11.3.x Systems
CVE-2021-22745
3.9LOW
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 26 May 2021
Summary
A vulnerability has been identified in the Triconex Model 3009 MP, which is present in Tricon V11.3.x systems. This issue arises from improper checks for unusual or exceptional conditions, leading to potential module resets when the Tricon Communication Module (TCM) encounters malformed TriStation packets while the write-protect keyswitch is set to the program position. It is important to assess system configurations and implement safeguards to mitigate the potential impact of this vulnerability.
Affected Version(s)
Triconex Model 3009 MP installed on Tricon V11.3.x systems Triconex Model 3009 MP installed on Tricon V11.3.x systems
References
CVSS V3.1
Score:
3.9
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved