ID

VAR-202109-0204


CVE

CVE-2021-22792


TITLE

plural  Schneider Electric  In the product  NULL  Pointer dereference vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2021-011449

DESCRIPTION

A CWE-476: NULL Pointer Dereference vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all versions), Modicon MC80 (part numbers BMKC80*, all versions), Modicon Momentum Ethernet CPU (part numbers 171CBU*, all versions), PLC Simulator for EcoStruxureª Control Expert, including all Unity Pro versions (former name of EcoStruxureª Control Expert, all versions), PLC Simulator for EcoStruxureª Process Expert including all HDCS versions (former name of EcoStruxureª Process Expert, all versions), Modicon Quantum CPU (part numbers 140CPU*, all versions), Modicon Premium CPU (part numbers TSXP5*, all versions). plural Schneider Electric The product has NULL There is a vulnerability in pointer dereference.Service operation interruption (DoS) It may be in a state

Trust: 1.71

sources: NVD: CVE-2021-22792 // JVNDB: JVNDB-2021-011449 // VULMON: CVE-2021-22792

AFFECTED PRODUCTS

vendor:schneider electricmodel:modicon m580 bmeh584040sscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmeh582040scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep581020scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon premium tsxp57 454mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmeh586040scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep582020hscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmeh584040scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon mc80 bmkc8030311scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep585040cscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep582040hscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep584040sscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon premium tsxp57 2634mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep582020scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmeh584040cscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmeh586040cscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep586040cscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon quantum 140cpu65150cscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep584040scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon premium tsxp57 1634mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon premium tsxp57 554mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon momentum 171cbu78090scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxp342030scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep585040scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmeh582040cscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon quantum 140cpu65160scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmeh582040sscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:plc simulator for ecostruxure process expertscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxp342010scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon momentum 171cbu98090scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon mc80 bmkc8020301scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon momentum 171cbu98091scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon premium tsxp57 2834mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxp342020scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon premium tsxp57 4634mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxp341000scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep582040sscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep582040scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep584020scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon quantum 140cpu65150scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep581020hscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep583040scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:plc simulator for ecostruxure control expertscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon premium tsxp57 5634mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon quantum 140cpu65160cscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon mc80 bmkc8020310scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon premium tsxp57 6634mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep586040scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmep583020scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmeh586040sscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxp342010scope: - version: -

Trust: 0.8

vendor:schneider electricmodel:modicon m580 bmeh584040scope: - version: -

Trust: 0.8

vendor:schneider electricmodel:modicon m580 bmeh582040cscope: - version: -

Trust: 0.8

vendor:schneider electricmodel:modicon m580 bmeh584040cscope: - version: -

Trust: 0.8

vendor:schneider electricmodel:modicon m580 bmeh584040sscope: - version: -

Trust: 0.8

vendor:schneider electricmodel:modicon m580 bmeh582040sscope: - version: -

Trust: 0.8

vendor:schneider electricmodel:modicon m340 bmxp342030scope: - version: -

Trust: 0.8

vendor:schneider electricmodel:modicon m340 bmxp342020scope: - version: -

Trust: 0.8

vendor:schneider electricmodel:modicon m340 bmxp341000scope: - version: -

Trust: 0.8

vendor:schneider electricmodel:modicon m580 bmeh582040scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2021-011449 // NVD: CVE-2021-22792

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-22792
value: HIGH

Trust: 1.0

NVD: CVE-2021-22792
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202109-129
value: HIGH

Trust: 0.6

VULMON: CVE-2021-22792
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2021-22792
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

nvd@nist.gov: CVE-2021-22792
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: CVE-2021-22792
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULMON: CVE-2021-22792 // JVNDB: JVNDB-2021-011449 // CNNVD: CNNVD-202109-129 // NVD: CVE-2021-22792

PROBLEMTYPE DATA

problemtype:CWE-476

Trust: 1.0

problemtype:NULL Pointer dereference (CWE-476) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2021-011449 // NVD: CVE-2021-22792

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202109-129

TYPE

code problem

Trust: 0.6

sources: CNNVD: CNNVD-202109-129

PATCH

title:SEVD-2021-222-04url:https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-222-04

Trust: 0.8

title:Schneider Electric Modicon M580 CPU Fixes for code issue vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=161395

Trust: 0.6

sources: JVNDB: JVNDB-2021-011449 // CNNVD: CNNVD-202109-129

EXTERNAL IDS

db:NVDid:CVE-2021-22792

Trust: 3.3

db:SCHNEIDERid:SEVD-2021-222-04

Trust: 1.7

db:SCHNEIDERid:SEVD-2021-222-07

Trust: 1.7

db:JVNDBid:JVNDB-2021-011449

Trust: 0.8

db:CNNVDid:CNNVD-202109-129

Trust: 0.6

db:VULMONid:CVE-2021-22792

Trust: 0.1

sources: VULMON: CVE-2021-22792 // JVNDB: JVNDB-2021-011449 // CNNVD: CNNVD-202109-129 // NVD: CVE-2021-22792

REFERENCES

url:https://download.schneider-electric.com/files?p_doc_ref=sevd-2021-222-07

Trust: 1.7

url:https://download.schneider-electric.com/files?p_doc_ref=sevd-2021-222-04

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2021-22792

Trust: 0.8

url:https://cwe.mitre.org/data/definitions/476.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULMON: CVE-2021-22792 // JVNDB: JVNDB-2021-011449 // CNNVD: CNNVD-202109-129 // NVD: CVE-2021-22792

SOURCES

db:VULMONid:CVE-2021-22792
db:JVNDBid:JVNDB-2021-011449
db:CNNVDid:CNNVD-202109-129
db:NVDid:CVE-2021-22792

LAST UPDATE DATE

2024-08-14T14:31:38.508000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2021-22792date:2021-09-13T00:00:00
db:JVNDBid:JVNDB-2021-011449date:2022-07-29T07:29:00
db:CNNVDid:CNNVD-202109-129date:2021-09-14T00:00:00
db:NVDid:CVE-2021-22792date:2021-09-13T18:14:53.380

SOURCES RELEASE DATE

db:VULMONid:CVE-2021-22792date:2021-09-02T00:00:00
db:JVNDBid:JVNDB-2021-011449date:2022-07-29T00:00:00
db:CNNVDid:CNNVD-202109-129date:2021-09-02T00:00:00
db:NVDid:CVE-2021-22792date:2021-09-02T17:15:08.343