Information Leakage in Modicon X80 by Schneider Electric
CVE-2021-22749
5.3MEDIUM
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 11 June 2021
Summary
A vulnerability exists in Schneider Electric's Modicon X80 BMXNOR0200H RTU that allows unauthorized actors to gain access to sensitive information regarding the RTU's current configuration, including communication parameters intended for telemetry purposes. This information can be exposed when the web server of the module receives a specially crafted HTTP request, potentially leading to further exploitation.
Affected Version(s)
Modicon X80 BMXNOR0200H RTU SV1.70 IR22 and prior Modicon X80 BMXNOR0200H RTU SV1.70 IR22 and prior
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved