Vulnerability Description
Improper Input Validation vulnerability exists in Modicon M241/M251 logic controllers firmware prior to V5.1.9.1 that could cause denial of service when specific crafted requests are sent to the controller over HTTP.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Modicon M241 Firmware | < 5.1.9.1 |
| Schneider-Electric | Modicon M241 | - |
| Schneider-Electric | Modicon M251 Firmware | < 5.1.9.1 |
| Schneider-Electric | Modicon M251 | - |
Related Weaknesses (CWE)
References
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-130-05Vendor Advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-130-05Vendor Advisory
FAQ
What is CVE-2021-22699?
CVE-2021-22699 is a vulnerability with a CVSS score of 7.5 (HIGH). Improper Input Validation vulnerability exists in Modicon M241/M251 logic controllers firmware prior to V5.1.9.1 that could cause denial of service when specific crafted requests are sent to the contr...
How severe is CVE-2021-22699?
CVE-2021-22699 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-22699?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Modicon M241 Firmware, Schneider-Electric Modicon M241, Schneider-Electric Modicon M251 Firmware, Schneider-Electric Modicon M251.