A CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service on ports 80 (HTTP) and 502 (Modbus), when sending a large number of TCP RST or FIN packets to any open TCP port of the PLC. Affected Product: Modicon M340 CPUs: BMXP34 (All Versions)
References
Link | Resource |
---|---|
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-011-01 | Mitigation Patch Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: schneider
Published: 2022-02-04T22:29:36
Updated: 2022-02-04T22:29:36
Reserved: 2022-01-06T00:00:00
Link: CVE-2022-22724
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-02-04T23:15:13.160
Modified: 2022-02-25T18:49:33.627
Link: CVE-2022-22724
JSON object: View
Redhat Information
No data.
CWE