Improper Condition Check in Triconex Model 3009 MP Affects Schneider Electric
CVE-2021-22746

3.9LOW

Key Information:

Summary

A vulnerability exists in Schneider Electric's Triconex Model 3009 MP that leads to potential disruptions in system operations. When this device operates with Tricon V11.3.x, it becomes susceptible to module resets upon receiving malformed TriStation packets, particularly when the write-protect keyswitch is in the program position. This flaw emphasizes the importance of proper validation checks to maintain the functionality and security of industrial control systems.

Affected Version(s)

Triconex Model 3009 MP installed on Tricon V11.3.x systems Triconex Model 3009 MP installed on Tricon V11.3.x systems

References

CVSS V3.1

Score:
3.9
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.