Information Leakage in Modicon X80 by Schneider Electric
CVE-2021-22749

5.3MEDIUM

Key Information:

Vendor
CVE Published:
11 June 2021

Summary

A vulnerability exists in Schneider Electric's Modicon X80 BMXNOR0200H RTU that allows unauthorized actors to gain access to sensitive information regarding the RTU's current configuration, including communication parameters intended for telemetry purposes. This information can be exposed when the web server of the module receives a specially crafted HTTP request, potentially leading to further exploitation.

Affected Version(s)

Modicon X80 BMXNOR0200H RTU SV1.70 IR22 and prior Modicon X80 BMXNOR0200H RTU SV1.70 IR22 and prior

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.