ID

VAR-202109-0206


CVE

CVE-2021-22789


TITLE

plural  Schneider Electric  Buffer error vulnerability in the product

Trust: 0.8

sources: JVNDB: JVNDB-2021-011448

DESCRIPTION

A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all versions), Modicon MC80 (part numbers BMKC80*, all versions), Modicon Momentum Ethernet CPU (part numbers 171CBU*, all versions), PLC Simulator for EcoStruxureª Control Expert, including all Unity Pro versions (former name of EcoStruxureª Control Expert, all versions), PLC Simulator for EcoStruxureª Process Expert including all HDCS versions (former name of EcoStruxureª Process Expert, all versions), Modicon Quantum CPU (part numbers 140CPU*, all versions), Modicon Premium CPU (part numbers TSXP5*, all versions). plural Schneider Electric The product contains a buffer error vulnerability.Service operation interruption (DoS) It may be in a state

Trust: 1.71

sources: NVD: CVE-2021-22789 // JVNDB: JVNDB-2021-011448 // VULMON: CVE-2021-22789

AFFECTED PRODUCTS

vendor:schneider electricmodel:modicon m580 bmeh584040sscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmeh582040scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep581020scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon premium tsxp57 454mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmeh586040scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep582020hscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmeh584040scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon mc80 bmkc8030311scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep585040cscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep582040hscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep584040sscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon premium tsxp57 2634mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep582020scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmeh584040cscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmeh586040cscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep586040cscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon quantum 140cpu65150cscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep584040scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon premium tsxp57 1634mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon premium tsxp57 554mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon momentum 171cbu78090scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxp342030scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep585040scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmeh582040cscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon quantum 140cpu65160scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmeh582040sscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:plc simulator for ecostruxure process expertscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxp342010scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon momentum 171cbu98090scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon mc80 bmkc8020301scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon momentum 171cbu98091scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon premium tsxp57 2834mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxp342020scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon premium tsxp57 4634mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxp341000scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep582040sscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep582040scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep584020scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon quantum 140cpu65150scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep581020hscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep583040scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:plc simulator for ecostruxure control expertscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon premium tsxp57 5634mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon quantum 140cpu65160cscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon mc80 bmkc8020310scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon premium tsxp57 6634mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep586040scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep583020scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmeh586040sscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxp342010scope: - version: -

Trust: 0.8

vendor:schneider electricmodel:modicon m580 bmeh584040scope: - version: -

Trust: 0.8

vendor:schneider electricmodel:modicon m580 bmeh582040cscope: - version: -

Trust: 0.8

vendor:schneider electricmodel:modicon m580 bmeh584040cscope: - version: -

Trust: 0.8

vendor:schneider electricmodel:modicon m580 bmeh584040sscope: - version: -

Trust: 0.8

vendor:schneider electricmodel:modicon m580 bmeh582040sscope: - version: -

Trust: 0.8

vendor:schneider electricmodel:modicon m340 bmxp342030scope: - version: -

Trust: 0.8

vendor:schneider electricmodel:modicon m340 bmxp342020scope: - version: -

Trust: 0.8

vendor:schneider electricmodel:modicon m340 bmxp341000scope: - version: -

Trust: 0.8

vendor:schneider electricmodel:modicon m580 bmeh582040scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2021-011448 // NVD: CVE-2021-22789

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-22789
value: MEDIUM

Trust: 1.0

NVD: CVE-2021-22789
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202109-126
value: MEDIUM

Trust: 0.6

VULMON: CVE-2021-22789
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2021-22789
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

nvd@nist.gov: CVE-2021-22789
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: CVE-2021-22789
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULMON: CVE-2021-22789 // JVNDB: JVNDB-2021-011448 // CNNVD: CNNVD-202109-126 // NVD: CVE-2021-22789

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.0

problemtype:Buffer error (CWE-119) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2021-011448 // NVD: CVE-2021-22789

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202109-126

TYPE

buffer error

Trust: 0.6

sources: CNNVD: CNNVD-202109-126

PATCH

title:SEVD-2021-222-04url:https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-222-04

Trust: 0.8

title:Schneider Electric Modicon M580 CPU Buffer error vulnerability fixurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=161392

Trust: 0.6

sources: JVNDB: JVNDB-2021-011448 // CNNVD: CNNVD-202109-126

EXTERNAL IDS

db:NVDid:CVE-2021-22789

Trust: 3.3

db:SCHNEIDERid:SEVD-2021-222-04

Trust: 1.7

db:JVNDBid:JVNDB-2021-011448

Trust: 0.8

db:CNNVDid:CNNVD-202109-126

Trust: 0.6

db:VULMONid:CVE-2021-22789

Trust: 0.1

sources: VULMON: CVE-2021-22789 // JVNDB: JVNDB-2021-011448 // CNNVD: CNNVD-202109-126 // NVD: CVE-2021-22789

REFERENCES

url:https://download.schneider-electric.com/files?p_doc_ref=sevd-2021-222-04

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2021-22789

Trust: 0.8

url:https://cwe.mitre.org/data/definitions/119.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULMON: CVE-2021-22789 // JVNDB: JVNDB-2021-011448 // CNNVD: CNNVD-202109-126 // NVD: CVE-2021-22789

SOURCES

db:VULMONid:CVE-2021-22789
db:JVNDBid:JVNDB-2021-011448
db:CNNVDid:CNNVD-202109-126
db:NVDid:CVE-2021-22789

LAST UPDATE DATE

2024-08-14T14:31:38.430000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2021-22789date:2021-09-13T00:00:00
db:JVNDBid:JVNDB-2021-011448date:2022-07-29T07:29:00
db:CNNVDid:CNNVD-202109-126date:2021-09-14T00:00:00
db:NVDid:CVE-2021-22789date:2021-09-13T18:35:03.837

SOURCES RELEASE DATE

db:VULMONid:CVE-2021-22789date:2021-09-02T00:00:00
db:JVNDBid:JVNDB-2021-011448date:2022-07-29T00:00:00
db:CNNVDid:CNNVD-202109-126date:2021-09-02T00:00:00
db:NVDid:CVE-2021-22789date:2021-09-02T17:15:08.180