IM
IronMonkey Threat Research

CVE-2021-22742 LOW

Published: 2021-05-26 | Last Modified: 2024-11-21 | Status: Modified

Description

Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position.

Additional Descriptions (1)

Existe una vulnerabilidad de comprobación inadecuada de condiciones inusuales o excepcionales en el modelo 3009 MP de Triconex instalado en sistemas Tricon versión V11.3.x que podría provocar el reinicio del módulo cuando el TCM recibe paquetes TriStation malformados mientras el interruptor de llave de protección contra escritura está en la posición de programa

CVSS Metrics

Base Score: 3.9 (LOW)

CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Attack VectorPHYSICAL
Attack ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 0.3

Impact Score: 3.6

Base Score: 2.1 (LOW)

AV:L/AC:L/Au:N/C:N/I:N/A:P

Access VectorLOCAL
Access ComplexityLOW
AuthenticationNONE
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 2.9

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-754
[email protected] Primary
en CWE-754

Affected Products

Vendor Product Version Update Type
schneider-electric triconex_model_3009_mp_firmware * <built-in method update of dict object at 0x7e60e8342dc0> Operating System
schneider-electric tcm_4351b_firmware * <built-in method update of dict object at 0x7e60a88a9400> Operating System
schneider-electric tcm_4351b_firmware 11.7.0 <built-in method update of dict object at 0x7e60a8a57a00> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:triconex_model_3009_mp_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:triconex_model_3009_mp:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:tcm_4351b_firmware:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:schneider-electric:tcm_4351b_firmware:11.7.0:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:tcm_4351b:-:*:*:*:*:*:*:*
Notification
Message here