Authentication Bypass Vulnerability in EcoStruxure Controllers by Schneider Electric
CVE-2022-45789
Key Information:
- Vendor
Schneider Electric
- Status
- Vendor
- CVE Published:
- 31 January 2023
What is CVE-2022-45789?
An authentication bypass vulnerability allows unauthorized execution of Modbus functions on Schneider Electric controllers. By hijacking an authenticated Modbus session, attackers can exploit this flaw, enabling them to execute unauthorized commands across various EcoStruxure products, including EcoStruxure Control Expert and EcoStruxure Process Expert, as well as Modicon CPUs. This poses significant risks to industrial control systems and requires immediate attention to secure affected systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
EcoStruxure Control Expert All Versions
EcoStruxure Process Expert All Versions
Modicon M340 CPU (part numbers BMXP34*) All Versions
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved