Insufficient Data Authenticity Verification in X80 Advanced RTU Communication Module by Schneider Electric
CVE-2022-34763
5.9MEDIUM
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 13 July 2022
Summary
A vulnerability exists in Schneider Electric’s X80 advanced RTU Communication Module and OPC UA Modicon Communication Module, stemming from insufficient verification of data authenticity. This flaw allows unauthorized firmware images to be loaded, potentially compromising the integrity of the devices. The issue affects specific versions of the communication modules, emphasizing the need for users to ensure firmware authenticity to safeguard against security breaches.
Affected Version(s)
OPC UA Modicon Communication Module BMENUA0100
X80 advanced RTU Communication Module V2.01
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved