Vulnerability Description
A CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service on ports 80 (HTTP) and 502 (Modbus), when sending a large number of TCP RST or FIN packets to any open TCP port of the PLC. Affected Product: Modicon M340 CPUs: BMXP34 (All Versions)
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Modicon M340 Bmxp341000 Firmware | - |
| Schneider-Electric | Modicon M340 Bmxp341000 | - |
| Schneider-Electric | Modicon M340 Bmxp342000 Firmware | - |
| Schneider-Electric | Modicon M340 Bmxp342000 | - |
| Schneider-Electric | Modicon M340 Bmxp342010 Firmware | - |
| Schneider-Electric | Modicon M340 Bmxp342010 | - |
| Schneider-Electric | Modicon M340 Bmxp3420102 Firmware | - |
| Schneider-Electric | Modicon M340 Bmxp3420102 | - |
| Schneider-Electric | Modicon M340 Bmxp342030 Firmware | - |
| Schneider-Electric | Modicon M340 Bmxp342030 | - |
| Schneider-Electric | Modicon M340 Bmxp3420302 Firmware | - |
| Schneider-Electric | Modicon M340 Bmxp3420302 | - |
Related Weaknesses (CWE)
References
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-011-01MitigationPatchVendor Advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-011-01MitigationPatchVendor Advisory
FAQ
What is CVE-2022-22724?
CVE-2022-22724 is a vulnerability with a CVSS score of 7.5 (HIGH). A CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service on ports 80 (HTTP) and 502 (Modbus), when sending a large number of TCP RST or FIN packets to any...
How severe is CVE-2022-22724?
CVE-2022-22724 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-22724?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Modicon M340 Bmxp341000 Firmware, Schneider-Electric Modicon M340 Bmxp341000, Schneider-Electric Modicon M340 Bmxp342000 Firmware, Schneider-Electric Modicon M340 Bmxp342000, Schneider-Electric Modicon M340 Bmxp342010 Firmware.