CVE-2022-45789
published 2023-01-31CVE-2022-45789: A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller when…
PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.44%
70.3th percentile
A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session. Affected Products: EcoStruxure Control Expert (All Versions), EcoStruxure Process Expert (All Versions), Modicon M340 CPU - part numbers BMXP34* (All Versions), Modicon M580 CPU - part numbers BMEP* and BMEH* (All Versions), Modicon M580 CPU Safety - part numbers BMEP58*S and BMEH58*S (All Versions)
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | ecostruxure_process_expert | <= 2020 | — |
| schneider_electric | ecostruxure_control_expert | — | — |
| schneider_electric | ecostruxure_process_expert | — | — |
| schneider_electric | modicon_m340_cpu | — | — |
| schneider_electric | modicon_m580_cpu | — | — |
| schneider_electric | modicon_m580_cpu_safety | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for unauthorized or replayed Modbus function codes on TCP/502 sessions — the attack hijacks an already-authenticated Modbus session via capture-replay to execute arbitrary Modbus functions on the controller. ↗
- →Alert on Modbus traffic (TCP/502) originating from hosts that are not the designated engineering workstation or known authorized clients, as the attacker replays captured authenticated sessions from a third-party network position. ↗
- →Detect duplicate or out-of-sequence Modbus session tokens/transaction IDs on TCP/502, which may indicate a capture-replay attack replaying a previously observed authenticated exchange. ↗
- ·EcoStruxure Process Expert V2021 is the only software release confirmed not impacted, as the vulnerable component was removed; all earlier versions remain exposed. ↗
- ·Attack complexity is rated HIGH (AC:H in CVSS vector), meaning exploitation requires the attacker to first capture a legitimate authenticated Modbus session before replaying it. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c7w2-f8m6-pxp8: A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller
ghsa_unreviewed·2023-07-06
CVE-2022-45789 [CRITICAL] CWE-294 GHSA-c7w2-f8m6-pxp8: A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller
A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session. Affected Products: EcoStruxure™ Control Expert (All Versions), EcoStruxure™ Process Expert (Version V2020 & prior), Modicon M340 CPU (part numbers BMXP34*) (All Versions), Modicon M580 CPU (part numbers BMEP* and BMEH*) (All Versions), Modicon M580 CPU Safety (part numbers BMEP58*S and BMEH58*S) (All Versions)
CISA ICS
Schneider Electric EcoStruxure Control Expert, Process Expert, Modicon M340, M580 and M580 CPU
cisa_ics·2023-08-15·CVSS 8.1
[HIGH] Schneider Electric EcoStruxure Control Expert, Process Expert, Modicon M340, M580 and M580 CPU
ICS Advisory
##
Schneider Electric EcoStruxure Control Expert, Process Expert, Modicon M340, M580 and M580 CPU
Release DateAugust 15, 2023
Alert CodeICSA-23-227-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.1
- ATTENTION: Exploitable remotely
- Vendor: Schneider Electric
- Equipment: EcoStruxure Control Expert, EcoStruxure Process Expert, Modicon M340 CPU, Modicon M580 CPU, Modicon Momentum Unity M1E Processor, Modicon MC80
- Vulnerability: Authentication Bypass by Capture-replay
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to execute unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following components of Schneider
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-010-06&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-010-06_Modicon_Controllers_Security_Notification.pdfhttps://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-010-06&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-010-06_Modicon_Controllers_Security_Notification.pdf
2023-01-31
Published