CVE-2022-22724
Summary
| CVE | CVE-2022-22724 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-04 23:15:00 UTC |
| Updated | 2022-02-25 18:49:00 UTC |
| Description | A CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service on ports 80 (HTTP) and 502 (Modbus), when sending a large number of TCP RST or FIN packets to any open TCP port of the PLC. Affected Product: Modicon M340 CPUs: BMXP34 (All Versions) |
Risk And Classification
Problem Types: CWE-400
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Schneider-electric | Modicon M340 Bmxp341000 | - | All | All | All |
| Operating System | Schneider-electric | Modicon M340 Bmxp341000 Firmware | - | All | All | All |
| Hardware | Schneider-electric | Modicon M340 Bmxp342000 | - | All | All | All |
| Operating System | Schneider-electric | Modicon M340 Bmxp342000 Firmware | - | All | All | All |
| Hardware | Schneider-electric | Modicon M340 Bmxp342010 | - | All | All | All |
| Hardware | Schneider-electric | Modicon M340 Bmxp3420102 | - | All | All | All |
| Operating System | Schneider-electric | Modicon M340 Bmxp3420102 Firmware | - | All | All | All |
| Operating System | Schneider-electric | Modicon M340 Bmxp342010 Firmware | - | All | All | All |
| Hardware | Schneider-electric | Modicon M340 Bmxp342030 | - | All | All | All |
| Hardware | Schneider-electric | Modicon M340 Bmxp3420302 | - | All | All | All |
| Operating System | Schneider-electric | Modicon M340 Bmxp3420302 Firmware | - | All | All | All |
| Operating System | Schneider-electric | Modicon M340 Bmxp342030 Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| download.schneider-electric.com/files | MISC | download.schneider-electric.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590823 Schneider Electric Ethernet and Web server on Modicon M340 controller and Communication Modules Multiple Vulnerabilities (SEVD-2022-011-01)