CVE-2021-22788
published 2022-02-11CVE-2021-22788: A CWE-787: Out-of-bounds Write vulnerability exists that could cause denial of service when an attacker sends a specially crafted HTTP request to the web…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.03%
59.8th percentile
A CWE-787: Out-of-bounds Write vulnerability exists that could cause denial of service when an attacker sends a specially crafted HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs: BMXP34 (Versions prior to V3.40), Modicon M340 X80 Ethernet Communication Modules: BMXNOE0100 (H), BMXNOE0110 (H), BMXNOC0401, BMXNOR0200H RTU (All Versions), Modicon Premium Processors with integrated Ethernet (Copro): TSXP574634, TSXP575634, TSXP576634 (All Versions), Modicon Quantum Processors with Integrated Ethernet (Copro): 140CPU65xxxxx (All Versions), Modicon Quantum Communication Modules: 140NOE771x1, 140NOC78x00, 140NOC77101 (All Versions), Modicon Premium Communication Modules: TSXETY4103, TSXETY5103 (All Versions)
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | modicon_m340_bmxp342020_firmware | < 3.40 | 3.40 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Schneider Electric Modicon M340 CPU Web Server out-of-bounds write (SEVD-2021-257-02)
vuldb·2026-06-01·CVSS 7.5
CVE-2021-22788 [HIGH] Schneider Electric Modicon M340 CPU Web Server out-of-bounds write (SEVD-2021-257-02)
A vulnerability has been found in Schneider Electric Modicon M340 CPU, Modicon M340 X80 Ethernet Communication Module, Modicon Premium Processor, Modicon Quantum Processor, Modicon Quantum Communication Module and Modicon Premium Communication Module and classified as critical. Affected by this vulnerability is an unknown functionality of the component Web Server. Performing a manipulation results in out-of-bounds write.
This vulnerability is identified as CVE-2021-22788. The attack can only be performed from the local network. There is not any exploit available.
The affected component should be upgraded.
GHSA
GHSA-97cv-9c84-r79m: A CWE-787: Out-of-bounds Write vulnerability exists that could cause denial of service when an attacker sends a specially crafted HTTP request to the
ghsa_unreviewed·2022-02-12
CVE-2021-22788 [HIGH] CWE-787 GHSA-97cv-9c84-r79m: A CWE-787: Out-of-bounds Write vulnerability exists that could cause denial of service when an attacker sends a specially crafted HTTP request to the
A CWE-787: Out-of-bounds Write vulnerability exists that could cause denial of service when an attacker sends a specially crafted HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs: BMXP34 (Versions prior to V3.40), Modicon M340 X80 Ethernet Communication Modules: BMXNOE0100 (H), BMXNOE0110 (H), BMXNOC0401, BMXNOR0200H RTU (All Versions), Modicon Premium Processors with integrated Ethernet (Copro): TSXP574634, TSXP575634, TSXP576634 (All Versions), Modicon Quantum Processors with Integrated Ethernet (Copro): 140CPU65xxxxx (All Versions), Modicon Quantum Communication Modules: 140NOE771x1, 140NOC78x00, 140NOC77101 (All Versions), Modicon Premium Communication Modules: TSXETY4103, TSXETY5103 (All Versions)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-02-11
Published