Improper Condition Check in Triconex Model 3009 MP Affects Schneider Electric
CVE-2021-22746
3.9LOW
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 26 May 2021
Summary
A vulnerability exists in Schneider Electric's Triconex Model 3009 MP that leads to potential disruptions in system operations. When this device operates with Tricon V11.3.x, it becomes susceptible to module resets upon receiving malformed TriStation packets, particularly when the write-protect keyswitch is in the program position. This flaw emphasizes the importance of proper validation checks to maintain the functionality and security of industrial control systems.
Affected Version(s)
Triconex Model 3009 MP installed on Tricon V11.3.x systems Triconex Model 3009 MP installed on Tricon V11.3.x systems
References
CVSS V3.1
Score:
3.9
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved