ID

VAR-202109-0203


CVE

CVE-2021-22791


TITLE

plural  Schneider Electric  Out-of-bounds write vulnerabilities in the product

Trust: 0.8

sources: JVNDB: JVNDB-2021-011446

DESCRIPTION

A CWE-787: Out-of-bounds Write vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all versions), Modicon MC80 (part numbers BMKC80*, all versions), Modicon Momentum Ethernet CPU (part numbers 171CBU*, all versions), PLC Simulator for EcoStruxureª Control Expert, including all Unity Pro versions (former name of EcoStruxureª Control Expert, all versions), PLC Simulator for EcoStruxureª Process Expert including all HDCS versions (former name of EcoStruxureª Process Expert, all versions), Modicon Quantum CPU (part numbers 140CPU*, all versions), Modicon Premium CPU (part numbers TSXP5*, all versions). plural Schneider Electric The product contains a vulnerability related to out-of-bounds writes.Service operation interruption (DoS) It may be in a state

Trust: 1.71

sources: NVD: CVE-2021-22791 // JVNDB: JVNDB-2021-011446 // VULMON: CVE-2021-22791

AFFECTED PRODUCTS

vendor:schneider electricmodel:modicon m580 bmeh584040sscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmeh582040scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep581020scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon premium tsxp57 454mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmeh586040scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep582020hscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmeh584040scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon mc80 bmkc8030311scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep585040cscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep582040hscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep584040sscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon premium tsxp57 2634mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep582020scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmeh584040cscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmeh586040cscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep586040cscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon quantum 140cpu65150cscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep584040scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon premium tsxp57 1634mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon premium tsxp57 554mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon momentum 171cbu78090scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxp342030scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep585040scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmeh582040cscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon quantum 140cpu65160scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmeh582040sscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:plc simulator for ecostruxure process expertscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxp342010scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon momentum 171cbu98090scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon mc80 bmkc8020301scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon momentum 171cbu98091scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon premium tsxp57 2834mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxp342020scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon premium tsxp57 4634mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxp341000scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep582040sscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep582040scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep584020scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon quantum 140cpu65150scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep581020hscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep583040scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:plc simulator for ecostruxure control expertscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon premium tsxp57 5634mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon quantum 140cpu65160cscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon mc80 bmkc8020310scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon premium tsxp57 6634mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep586040scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep583020scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmeh586040sscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxp342010scope: - version: -

Trust: 0.8

vendor:schneider electricmodel:modicon m580 bmeh584040scope: - version: -

Trust: 0.8

vendor:schneider electricmodel:modicon m580 bmeh582040cscope: - version: -

Trust: 0.8

vendor:schneider electricmodel:modicon m580 bmeh584040cscope: - version: -

Trust: 0.8

vendor:schneider electricmodel:modicon m580 bmeh584040sscope: - version: -

Trust: 0.8

vendor:schneider electricmodel:modicon m580 bmeh582040sscope: - version: -

Trust: 0.8

vendor:schneider electricmodel:modicon m340 bmxp342030scope: - version: -

Trust: 0.8

vendor:schneider electricmodel:modicon m340 bmxp342020scope: - version: -

Trust: 0.8

vendor:schneider electricmodel:modicon m340 bmxp341000scope: - version: -

Trust: 0.8

vendor:schneider electricmodel:modicon m580 bmeh582040scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2021-011446 // NVD: CVE-2021-22791

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-22791
value: MEDIUM

Trust: 1.0

NVD: CVE-2021-22791
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202109-123
value: MEDIUM

Trust: 0.6

VULMON: CVE-2021-22791
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2021-22791
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

nvd@nist.gov: CVE-2021-22791
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: CVE-2021-22791
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULMON: CVE-2021-22791 // JVNDB: JVNDB-2021-011446 // CNNVD: CNNVD-202109-123 // NVD: CVE-2021-22791

PROBLEMTYPE DATA

problemtype:CWE-787

Trust: 1.0

problemtype:Out-of-bounds writing (CWE-787) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2021-011446 // NVD: CVE-2021-22791

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202109-123

TYPE

buffer error

Trust: 0.6

sources: CNNVD: CNNVD-202109-123

PATCH

title:SEVD-2021-222-04url:https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-222-04

Trust: 0.8

title:Multiple Schneider Electric Product Buffer Error Vulnerability Fixurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=161389

Trust: 0.6

sources: JVNDB: JVNDB-2021-011446 // CNNVD: CNNVD-202109-123

EXTERNAL IDS

db:NVDid:CVE-2021-22791

Trust: 3.3

db:SCHNEIDERid:SEVD-2021-222-04

Trust: 1.7

db:SCHNEIDERid:SEVD-2021-222-06

Trust: 1.7

db:JVNDBid:JVNDB-2021-011446

Trust: 0.8

db:CNNVDid:CNNVD-202109-123

Trust: 0.6

db:VULMONid:CVE-2021-22791

Trust: 0.1

sources: VULMON: CVE-2021-22791 // JVNDB: JVNDB-2021-011446 // CNNVD: CNNVD-202109-123 // NVD: CVE-2021-22791

REFERENCES

url:https://download.schneider-electric.com/files?p_doc_ref=sevd-2021-222-06

Trust: 1.7

url:https://download.schneider-electric.com/files?p_doc_ref=sevd-2021-222-04

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2021-22791

Trust: 0.8

url:https://cwe.mitre.org/data/definitions/787.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULMON: CVE-2021-22791 // JVNDB: JVNDB-2021-011446 // CNNVD: CNNVD-202109-123 // NVD: CVE-2021-22791

SOURCES

db:VULMONid:CVE-2021-22791
db:JVNDBid:JVNDB-2021-011446
db:CNNVDid:CNNVD-202109-123
db:NVDid:CVE-2021-22791

LAST UPDATE DATE

2024-08-14T14:31:38.481000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2021-22791date:2021-09-13T00:00:00
db:JVNDBid:JVNDB-2021-011446date:2022-07-29T07:29:00
db:CNNVDid:CNNVD-202109-123date:2021-09-14T00:00:00
db:NVDid:CVE-2021-22791date:2021-09-13T19:28:42.877

SOURCES RELEASE DATE

db:VULMONid:CVE-2021-22791date:2021-09-02T00:00:00
db:JVNDBid:JVNDB-2021-011446date:2022-07-29T00:00:00
db:CNNVDid:CNNVD-202109-123date:2021-09-02T00:00:00
db:NVDid:CVE-2021-22791date:2021-09-02T17:15:08.290