CVE-2021-22699
 
Severity Score
7.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Improper Input Validation vulnerability exists in Modicon M241/M251 logic controllers firmware prior to V5.1.9.1 that could cause denial of service when specific crafted requests are sent to the controller over HTTP.
Se presenta una vulnerabilidad de Comprobación Inapropiada de Entrada en los controladores lógicos Modicon M241/M251 versiones del firmware anteriores a V5.1.9.1, que podría causar una denegación de servicio cuando peticiones específicas diseñadas son enviadas al controlador a través de HTTP
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2021-01-06 CVE Reserved
- 2021-05-26 CVE Published
- 2024-02-09 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-130-05 | 2022-02-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Schneider-electric Search vendor "Schneider-electric" | Modicon M241 Firmware Search vendor "Schneider-electric" for product "Modicon M241 Firmware" | < 5.1.9.1 Search vendor "Schneider-electric" for product "Modicon M241 Firmware" and version " < 5.1.9.1" | - |
Affected
| in | Schneider-electric Search vendor "Schneider-electric" | Modicon M241 Search vendor "Schneider-electric" for product "Modicon M241" | - | - |
Safe
|
Schneider-electric Search vendor "Schneider-electric" | Modicon M251 Firmware Search vendor "Schneider-electric" for product "Modicon M251 Firmware" | < 5.1.9.1 Search vendor "Schneider-electric" for product "Modicon M251 Firmware" and version " < 5.1.9.1" | - |
Affected
| in | Schneider-electric Search vendor "Schneider-electric" | Modicon M251 Search vendor "Schneider-electric" for product "Modicon M251" | - | - |
Safe
|