CRITICAL · 9.1

CVE-2021-22779

Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Control Expert V15.0 SP1, EcoSt...

Vulnerability Description

Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Control Expert V15.0 SP1, EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), SCADAPack RemoteConnect for x70 (all versions), Modicon M580 CPU (all versions - part numbers BMEP* and BMEH*), Modicon M340 CPU (all versions - part numbers BMXP34*), that could cause unauthorized access in read and write mode to the controller by spoofing the Modbus communication between the engineering software and the controller.

CVSS Score

9.1

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
Schneider-ElectricEcostruxure Control Expert< 15.0
Schneider-ElectricEcostruxure Process ExpertAll versions
Schneider-ElectricRemoteconnectAll versions
Schneider-ElectricModicon M580 Bmep581020 FirmwareAll versions
Schneider-ElectricModicon M580 Bmep581020-
Schneider-ElectricModicon M580 Bmep581020H FirmwareAll versions
Schneider-ElectricModicon M580 Bmep581020H-
Schneider-ElectricModicon M580 Bmep582020 FirmwareAll versions
Schneider-ElectricModicon M580 Bmep582020-
Schneider-ElectricModicon M580 Bmep582020H FirmwareAll versions
Schneider-ElectricModicon M580 Bmep582020H-
Schneider-ElectricModicon M580 Bmep582040 FirmwareAll versions
Schneider-ElectricModicon M580 Bmep582040-
Schneider-ElectricModicon M580 Bmep582040H FirmwareAll versions
Schneider-ElectricModicon M580 Bmep582040H-
Schneider-ElectricModicon M580 Bmep582040S FirmwareAll versions
Schneider-ElectricModicon M580 Bmep582040S-
Schneider-ElectricModicon M580 Bmep583020 FirmwareAll versions
Schneider-ElectricModicon M580 Bmep583020-
Schneider-ElectricModicon M580 Bmep583040 FirmwareAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-22779?

CVE-2021-22779 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Control Expert V15.0 SP1, EcoSt...

How severe is CVE-2021-22779?

CVE-2021-22779 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2021-22779?

Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Ecostruxure Control Expert, Schneider-Electric Ecostruxure Process Expert, Schneider-Electric Remoteconnect, Schneider-Electric Modicon M580 Bmep581020 Firmware, Schneider-Electric Modicon M580 Bmep581020.