Weak Password Recovery Mechanism in EcoStruxure Control Expert and Modicon CPUs
CVE-2022-37300
9.8CRITICAL
What is CVE-2022-37300?
A vulnerability exists due to a weak password recovery mechanism that enables unauthorized access with read and write capabilities to the controller through Modbus communication. This can compromise the integrity and security of industrial control systems, affecting products like EcoStruxure Control Expert and various Modicon CPUs, posing significant risks for operational technology environments.
Affected Version(s)
EcoStruxure Control Expert SP1 <= 15.0
EcoStruxure Process Expert V <= 2021
Modicon M340 CPU BMXP34 <= 3.40