CVE Database
/

CVE-2022-37300

Back to search

CVE-2022-37300

Published: Sep 12, 2022

Modified: Aug 3, 2024

PUBLISHED

CVSS v3.1

9.8

CRITICAL

Description

A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communicating over Modbus. Affected Products: EcoStruxure Control Expert Including all Unity Pro versions (former name of EcoStruxure Control Expert) (V15.0 SP1 and prior), EcoStruxure Process Expert, Including all versions of EcoStruxure Hybrid DCS (former name of EcoStruxure Process Expert) (V2021 and prior), Modicon M340 CPU (part numbers BMXP34*) (V3.40 and prior), Modicon M580 CPU (part numbers BMEP* and BMEH*) (V3.20 and prior).

VendorProductVersions

Schneider Electric

EcoStruxure Control Expert

affected
SP1 - <= 15.0

Schneider Electric

EcoStruxure Process Expert

affected
V - <= 2021

Schneider Electric

Modicon M340 CPU

affected
BMXP34 - <= 3.40

Schneider Electric

Modicon M580 CPU

affected
BMEP - <= 3.20
affected
BMEH - <= 3.20

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now