Schneider-Electric X80 Advanced Rtu Module Firmware vulnerabilities
7 known vulnerabilities affecting schneider-electric/x80_advanced_rtu_module_firmware.
Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH6MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2022-34763HIGHCVSS 7.5≥ 2.012022-07-13
CVE-2022-34763 [MEDIUM] CWE-345 CVE-2022-34763: A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists that could cause load
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists that could cause loading of unauthorized firmware images due to improper verification of the firmware signature. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)
nvd
CVE-2022-34764HIGHCVSS 7.5v1.02022-07-13
CVE-2022-34764 [MEDIUM] CWE-119 CVE-2022-34764: A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exi
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service when parsing the URL. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V1.0), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)
nvd
CVE-2022-34762HIGHCVSS 7.5≥ 2.012022-07-13
CVE-2022-34762 [MEDIUM] CWE-22 CVE-2022-34762: A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerabili
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause unauthorized firmware image loading when unsigned images are added to the firmware image path. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA Modicon Communication Module (BME
nvd
CVE-2022-34760HIGHCVSS 7.5v1.02022-07-13
CVE-2022-34760 [HIGH] CWE-835 CVE-2022-34760: A CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability exists that could ca
A CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability exists that could cause a denial of service of the webserver due to improper handling of the cookies. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V1.0), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)
nvd
CVE-2022-34759HIGHCVSS 7.5v1.02022-07-13
CVE-2022-34759 [HIGH] CWE-787 CVE-2022-34759: A CWE-787: Out-of-bounds Write vulnerability exists that could cause a denial of service of the webs
A CWE-787: Out-of-bounds Write vulnerability exists that could cause a denial of service of the webserver due to improper parsing of the HTTP Headers. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V1.0), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)
nvd
CVE-2022-34761HIGHCVSS 7.5≥ 2.012022-07-13
CVE-2022-34761 [HIGH] CWE-476 CVE-2022-34761: A CWE-476: NULL Pointer Dereference vulnerability exists that could cause a denial of service of the
A CWE-476: NULL Pointer Dereference vulnerability exists that could cause a denial of service of the webserver when parsing JSON content type. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)
nvd
CVE-2022-34765MEDIUMCVSS 5.3≥ 2.012022-07-13
CVE-2022-34765 [MEDIUM] CWE-73 CVE-2022-34765: A CWE-73: External Control of File Name or Path vulnerability exists that could cause loading of una
A CWE-73: External Control of File Name or Path vulnerability exists that could cause loading of unauthorized firmware images when user-controlled data is written to the file path. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)
nvd