CVE-2021-22785
published 2022-02-11CVE-2021-22785: A CWE-200: Information Exposure vulnerability exists that could cause sensitive information of files located in the web root directory to leak when an attacker…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.95%
57.2th percentile
A CWE-200: Information Exposure vulnerability exists that could cause sensitive information of files located in the web root directory to leak when an attacker sends a HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs: BMXP34 (Versions prior to V3.40), Modicon M340 X80 Ethernet Communication Modules: BMXNOE0100 (H), BMXNOE0110 (H), BMXNOC0401, BMXNOR0200H RTU (All Versions), Modicon Premium Processors with integrated Ethernet (Copro): TSXP574634, TSXP575634, TSXP576634 (All Versions), Modicon Quantum Processors with Integrated Ethernet (Copro): 140CPU65xxxxx (All Versions), Modicon Quantum Communication Modules: 140NOE771x1, 140NOC78x00, 140NOC77101 (All Versions), Modicon Premium Communication Modules: TSXETY4103, TSXETY5103 (All Versions)
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | modicon_m340_bmxp342020_firmware | < 3.40 | 3.40 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Schneider Electric Modicon M340 CPU Web Server information disclosure (SEVD-2021-257-02)
vuldb·2026-06-01·CVSS 7.5
CVE-2021-22785 [HIGH] Schneider Electric Modicon M340 CPU Web Server information disclosure (SEVD-2021-257-02)
A vulnerability classified as problematic has been found in Schneider Electric Modicon M340 CPU, Modicon M340 X80 Ethernet Communication Module, Modicon Premium Processor, Modicon Quantum Processor, Modicon Quantum Communication Module and Modicon Premium Communication Module. This issue affects some unknown processing of the component Web Server. Performing a manipulation results in information disclosure.
This vulnerability was named CVE-2021-22785. The attack needs to be approached within the local network. There is no available exploit.
It is recommended to upgrade the affected component.
GHSA
GHSA-r2qw-hw78-874v: A CWE-200: Information Exposure vulnerability exists that could cause sensitive information of files located in the web root directory to leak when an
ghsa_unreviewed·2022-02-12
CVE-2021-22785 [HIGH] CWE-200 GHSA-r2qw-hw78-874v: A CWE-200: Information Exposure vulnerability exists that could cause sensitive information of files located in the web root directory to leak when an
A CWE-200: Information Exposure vulnerability exists that could cause sensitive information of files located in the web root directory to leak when an attacker sends a HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs: BMXP34 (Versions prior to V3.40), Modicon M340 X80 Ethernet Communication Modules: BMXNOE0100 (H), BMXNOE0110 (H), BMXNOC0401, BMXNOR0200H RTU (All Versions), Modicon Premium Processors with integrated Ethernet (Copro): TSXP574634, TSXP575634, TSXP576634 (All Versions), Modicon Quantum Processors with Integrated Ethernet (Copro): 140CPU65xxxxx (All Versions), Modicon Quantum Communication Modules: 140NOE771x1, 140NOC78x00, 140NOC77101 (All Versions), Modicon Premium Communication Modules: TSXETY4103, TSXETY5103 (All Versions)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-02-11
Published