cbcvebase.
CVE-2022-34762
published 2022-07-13

CVE-2022-34762: A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause unauthorized firmware image…

PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.67%
47.5th percentile
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause unauthorized firmware image loading when unsigned images are added to the firmware image path. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)

Affected

4 ranges
VendorProductVersion rangeFixed in
schneider-electricopc_ua_module_for_m580_firmware<= 1.10
schneider-electricx80_advanced_rtu_module_firmware>= 2.01
schneider_electricopc_ua_modicon_communication_module>= BMENUA0100 < V1.10V1.10
schneider_electricx80_advanced_rtu_communication_module>= V2.01 < BMENOR2200H*BMENOR2200H*
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.