CVE-2021-22779
published 2021-07-14CVE-2021-22779: Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro)…
PriorityP356critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
1.02%
59.7th percentile
Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Control Expert V15.0 SP1, EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), SCADAPack RemoteConnect for x70 (all versions), Modicon M580 CPU (all versions - part numbers BMEP* and BMEH*), Modicon M340 CPU (all versions - part numbers BMXP34*), that could cause unauthorized access in read and write mode to the controller by spoofing the Modbus communication between the engineering software and the controller.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | ecostruxure_control_expert | < 15.0 | 15.0 |
| schneider-electric | ecostruxure_control_expert | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric Modicon Controllers and Software (Update A)
cisa_ics·2021-07-13
Schneider Electric Modicon Controllers and Software (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric Modicon Controllers and Software (Update A)
Last RevisedJuly 27, 2021
Alert CodeICSA-21-194-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Schneider Electric
- Equipment: EcoStruxure Control Expert, EcoStruxure Process Expert, SCADAPack RemoteConnect x70, SCADAPack x70 RTUs, and Modicon M580 and M340 control products
- Vulnerabilities: Insufficiently Protected Credentials, Authentication Bypass by Spoofing, Deserialization of Untrusted Data, Missing Encryption of Sensitive Data.
## 2. UPDATE INFO
GHSA
GHSA-qx3c-87pm-wqpc: Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15
ghsa_unreviewed·2022-05-24
CVE-2021-22779 [CRITICAL] CWE-290 GHSA-qx3c-87pm-wqpc: Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15
Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Control Expert V15.0 SP1, EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), SCADAPack RemoteConnect for x70 (all versions), Modicon M580 CPU (all versions - part numbers BMEP* and BMEH*), Modicon M340 CPU (all versions - part numbers BMXP34*), that could cause unauthorized access in read and write mode to the controller by spoofing the Modbus communication between the engineering software and the controller.
No detection rules found.
No public exploits indexed.
Securelist
Schneider Electric UMAS protocol vulnerabilities
blogs_securelist·2022-09-29·CVSS 9.8
CVE-2020-28212 [CRITICAL] Schneider Electric UMAS protocol vulnerabilities
Table of Contents
- Object of research
- UMAS protocol
- CVE-2020-28212: authentication bypass without Application Password
- Application Password
Authors
- Kaspersky ICS CERT
UMAS (Unified Messaging Application Services) is a proprietary Schneider Electric (SE) protocol used to configure and monitor Schneider Electric PLCs. Schneider Electric controllers that use UMAS include Modicon M580 CPU (part numbers BMEP* and BMEH*) and Modicon M340 CPU (part numbers BMXP34*). Controllers are configured and programmed using engineering software – EcoStruxure™ Control Expert (Unity Pro), EcoStruxure™ Process Expert, etc.
In 2020, CVE-2020-28212, a vulnerability affecting this software, was reported, which could be exploited by a remote unauthorized attacker to gain control of a PLC with the pr
Securelist
The secrets of Schneider Electric’s UMAS protocol
blogs_securelist·2022-09-29·CVSS 9.8
CVE-2020-28212 [CRITICAL] The secrets of Schneider Electric’s UMAS protocol
Table of Contents
Object of research
UMAS protocol
Network packet structure
Network communication
Reservation procedure
CVE-2020-28212: authentication bypass without Application Password
Application Password
Authors
Kaspersky ICS CERT
UMAS (Unified Messaging Application Services) is a proprietary Schneider Electric (SE) protocol used to configure and monitor Schneider Electric PLCs. Schneider Electric controllers that use UMAS include Modicon M580 CPU (part numbers BMEP* and BMEH*) and Modicon M340 CPU (part numbers BMXP34*). Controllers are configured and programmed using engineering software – EcoStruxure™ Control Expert (Unity Pro), EcoStruxure™ Process Expert, etc.
In 2020, CVE-2020-28212 , a vulnerability affecting this software, was reported, which could be exploited by a
2021-07-14
Published