Vulnerability Description
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause a Denial of Service of the RTU when receiving a specially crafted request over Modbus, and the RTU is configured as a Modbus server. Affected Products: SCADAPack 312E, 313E, 314E, 330E, 333E, 334E, 337E, 350E and 357E RTUs with firmware V8.18.1 and prior
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Scadapack 312E Firmware | < 8.19.1 |
| Schneider-Electric | Scadapack 312E | - |
| Schneider-Electric | Scadapack 313E Firmware | < 8.19.1 |
| Schneider-Electric | Scadapack 313E | - |
| Schneider-Electric | Scadapack 314E Firmware | < 8.19.1 |
| Schneider-Electric | Scadapack 314E | - |
| Schneider-Electric | Scadapack 330E Firmware | < 8.19.1 |
| Schneider-Electric | Scadapack 330E | - |
| Schneider-Electric | Scadapack 333E Firmware | < 8.19.1 |
| Schneider-Electric | Scadapack 333E | - |
| Schneider-Electric | Scadapack 334E Firmware | < 8.19.1 |
| Schneider-Electric | Scadapack 334E | - |
| Schneider-Electric | Scadapack 337E Firmware | < 8.19.1 |
| Schneider-Electric | Scadapack 337E | - |
| Schneider-Electric | Scadapack 350E Firmware | < 8.19.1 |
| Schneider-Electric | Scadapack 350E | - |
| Schneider-Electric | Scadapack 357E Firmware | < 8.19.1 |
| Schneider-Electric | Scadapack 357E | - |
Related Weaknesses (CWE)
References
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-313-01Vendor Advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-313-01Vendor Advisory
FAQ
What is CVE-2021-22816?
CVE-2021-22816 is a vulnerability with a CVSS score of 7.5 (HIGH). A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause a Denial of Service of the RTU when receiving a specially crafted request over Modbus, and the RTU...
How severe is CVE-2021-22816?
CVE-2021-22816 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-22816?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Scadapack 312E Firmware, Schneider-Electric Scadapack 312E, Schneider-Electric Scadapack 313E Firmware, Schneider-Electric Scadapack 313E, Schneider-Electric Scadapack 314E Firmware.