IM
IronMonkey Threat Research

CVE-2022-24322 MEDIUM

Published: 2022-03-09 | Last Modified: 2024-11-21 | Status: Modified

Description

A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a disruption of communication between the Modicon controller and the engineering software when an attacker is able to intercept and manipulate specific Modbus response data. Affected Product: EcoStruxure Control Expert (V15.0 SP1 and prior)

Additional Descriptions (1)

Una CWE-119: Se presenta una vulnerabilidad de Restricción Inapropiada de las Operaciones dentro de los límites de un Búfer de Memoria que podría causar una interrupción de la comunicación entre el controlador Modicon y el software de ingeniería cuando un atacante es capaz de interceptar y manipular datos de respuesta Modbus específicos. Producto afectado: EcoStruxure Control Expert (versiones V15.0 SP1 y anteriores)

CVSS Metrics

Base Score: 5.9 (MEDIUM)

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack VectorNETWORK
Attack ComplexityHIGH
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactHIGH
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 2.2

Impact Score: 3.6

Base Score: 4.3 (MEDIUM)

AV:N/AC:M/Au:N/C:N/I:P/A:N

Access VectorNETWORK
Access ComplexityMEDIUM
AuthenticationNONE
Confidentiality ImpactNONE
Integrity ImpactPARTIAL
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 8.6

Impact Score: 2.9

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-119
[email protected] Primary
en CWE-119

Affected Products

Vendor Product Version Update Type
schneider-electric ecostruxure_control_expert * <built-in method update of dict object at 0x7e6110a57e00> Application
schneider-electric ecostruxure_control_expert 15.0 <built-in method update of dict object at 0x7e6110a55580> Application
schneider-electric ecostruxure_control_expert 15.0 <built-in method update of dict object at 0x7e6110a54080> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:schneider-electric:ecostruxure_control_expert:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:ecostruxure_control_expert:15.0:-:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:ecostruxure_control_expert:15.0:sp1:*:*:*:*:*:*
Notification
Message here