CVE-2021-22792

high-risk
Published 2021-09-02

A CWE-476: NULL Pointer Dereference vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all versions), Modicon MC80 (part numbers BMKC80*, all versions), Modicon Momentum Ethernet CPU (part numbers 171CBU*, all versions), PLC Simulator for EcoStruxureª Control Expert, including all Unity Pro versions (former name of EcoStruxureª Control Expert, all versions), PLC Simulator for EcoStruxureª Process Expert including all HDCS versions (former name of EcoStruxureª Process Expert, all versions), Modicon Quantum CPU (part numbers 140CPU*, all versions), Modicon Premium CPU (part numbers TSXP5*, all versions).

Do I need to act?

-
0.46% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10 High
NETWORK / LOW complexity

Affected Products (20)

Modicon M340 Bmxp341000
Modicon M340 Bmxp342010
Modicon M340 Bmxp342020
Modicon M340 Bmxp342030
Modicon M580 Bmeh582040
Modicon M580 Bmeh582040C
Modicon M580 Bmeh582040S
Modicon M580 Bmeh584040
Modicon M580 Bmeh584040C
Modicon M580 Bmeh584040S
Modicon M580 Bmeh586040
Modicon M580 Bmeh586040C
Modicon M580 Bmeh586040S
Modicon M580 Bmep581020
Modicon M580 Bmep581020H
Modicon M580 Bmep582020
Modicon M580 Bmep582020H
Modicon M580 Bmep582040
Modicon M580 Bmep582040H
Modicon M580 Bmep582040S

Affected Vendors

53
/ 100
high-risk
Severity 26/34 · High
Exploitability 2/34 · Minimal
Exposure 25/34 · High