ID

VAR-201602-0395


TITLE

Schneider Electric Modicon M580 EtherNetIP Protocol Stack Denial of Service Vulnerability

Trust: 0.2

sources: IVD: 324126d0-1e44-11e6-abef-000c29c66e3d

DESCRIPTION

Schneider Electric PLCModicon M580 It is an Ethernet programmable controller. Schneider Electric PLC modicon M580 use EtherNetIP Protocol for industrial control communication. With M580 When communicating EthernetIP protocol “Semrrdata” Message Command_specific_data Field is set to 0x0C Time EtherNetIP There are security holes in the protocol stack, but ping Still reachable, need to shut down and restart to recover EtherNetIP Agreement services. Allows an attacker to use this vulnerability to launch a denial of service attack.

Trust: 0.2

sources: IVD: 324126d0-1e44-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.2

sources: IVD: 324126d0-1e44-11e6-abef-000c29c66e3d

AFFECTED PRODUCTS

vendor:schneidermodel:electric modicon m580scope:eqversion:;*

Trust: 0.2

vendor:schneidermodel: - scope:eqversion:*

Trust: 0.2

vendor:schneidermodel:electric modicon m580;scope:eqversion:*

Trust: 0.2

sources: IVD: 324126d0-1e44-11e6-abef-000c29c66e3d

CVSS

SEVERITY

CVSSV2

CVSSV3

IVD: 324126d0-1e44-11e6-abef-000c29c66e3d
value: MEDIUM

Trust: 0.2

IVD: 324126d0-1e44-11e6-abef-000c29c66e3d
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.3 [IVD]

Trust: 0.2

sources: IVD: 324126d0-1e44-11e6-abef-000c29c66e3d

TYPE

Denial of service

Trust: 0.2

sources: IVD: 324126d0-1e44-11e6-abef-000c29c66e3d

EXTERNAL IDS

db:CNVDid:CNVD-2016-01429

Trust: 0.2

db:IVDid:324126D0-1E44-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: 324126d0-1e44-11e6-abef-000c29c66e3d

SOURCES

db:IVDid:324126d0-1e44-11e6-abef-000c29c66e3d

LAST UPDATE DATE

2022-05-17T01:57:43.434000+00:00


SOURCES UPDATE DATE


SOURCES RELEASE DATE

db:IVDid:324126d0-1e44-11e6-abef-000c29c66e3ddate:2016-02-29T00:00:00