// For flags

CVE-2021-22749

 

Severity Score

5.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Modicon X80 BMXNOR0200H RTU SV1.70 IR22 and prior that could cause information leak concerning the current RTU configuration including communication parameters dedicated to telemetry, when a specially crafted HTTP request is sent to the web server of the module.

Un CWE-787: Se presenta una vulnerabilidad de Exposición de Información Confidencial a un Actor No Autorizado en Modicon X80 BMXNOR0200H RTU versiones SV1.70 IR22 y anteriores, que podría provocar un filtrado de información relativa a la configuración actual de la RTU, incluidos los parámetros de comunicación dedicados a la telemetría, cuando se envía una petición HTTP especialmente diseñada al servidor web del módulo

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-01-06 CVE Reserved
  • 2021-06-11 CVE Published
  • 2024-04-19 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Schneider-electric
Search vendor "Schneider-electric"
Modicon X80 Bmxnor0200h Rtu Firmware
Search vendor "Schneider-electric" for product "Modicon X80 Bmxnor0200h Rtu Firmware"
sv1.6
Search vendor "Schneider-electric" for product "Modicon X80 Bmxnor0200h Rtu Firmware" and version "sv1.6"
ir4
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Modicon X80 Bmxnor0200h Rtu
Search vendor "Schneider-electric" for product "Modicon X80 Bmxnor0200h Rtu"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Modicon X80 Bmxnor0200h Rtu Firmware
Search vendor "Schneider-electric" for product "Modicon X80 Bmxnor0200h Rtu Firmware"
sv1.7
Search vendor "Schneider-electric" for product "Modicon X80 Bmxnor0200h Rtu Firmware" and version "sv1.7"
ir10
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Modicon X80 Bmxnor0200h Rtu
Search vendor "Schneider-electric" for product "Modicon X80 Bmxnor0200h Rtu"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Modicon X80 Bmxnor0200h Rtu Firmware
Search vendor "Schneider-electric" for product "Modicon X80 Bmxnor0200h Rtu Firmware"
sv1.7
Search vendor "Schneider-electric" for product "Modicon X80 Bmxnor0200h Rtu Firmware" and version "sv1.7"
ir15b
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Modicon X80 Bmxnor0200h Rtu
Search vendor "Schneider-electric" for product "Modicon X80 Bmxnor0200h Rtu"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Modicon X80 Bmxnor0200h Rtu Firmware
Search vendor "Schneider-electric" for product "Modicon X80 Bmxnor0200h Rtu Firmware"
sv1.7
Search vendor "Schneider-electric" for product "Modicon X80 Bmxnor0200h Rtu Firmware" and version "sv1.7"
ir17
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Modicon X80 Bmxnor0200h Rtu
Search vendor "Schneider-electric" for product "Modicon X80 Bmxnor0200h Rtu"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Modicon X80 Bmxnor0200h Rtu Firmware
Search vendor "Schneider-electric" for product "Modicon X80 Bmxnor0200h Rtu Firmware"
sv1.7
Search vendor "Schneider-electric" for product "Modicon X80 Bmxnor0200h Rtu Firmware" and version "sv1.7"
ir18
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Modicon X80 Bmxnor0200h Rtu
Search vendor "Schneider-electric" for product "Modicon X80 Bmxnor0200h Rtu"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Modicon X80 Bmxnor0200h Rtu Firmware
Search vendor "Schneider-electric" for product "Modicon X80 Bmxnor0200h Rtu Firmware"
sv1.7
Search vendor "Schneider-electric" for product "Modicon X80 Bmxnor0200h Rtu Firmware" and version "sv1.7"
ir19
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Modicon X80 Bmxnor0200h Rtu
Search vendor "Schneider-electric" for product "Modicon X80 Bmxnor0200h Rtu"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Modicon X80 Bmxnor0200h Rtu Firmware
Search vendor "Schneider-electric" for product "Modicon X80 Bmxnor0200h Rtu Firmware"
sv1.7
Search vendor "Schneider-electric" for product "Modicon X80 Bmxnor0200h Rtu Firmware" and version "sv1.7"
ir20
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Modicon X80 Bmxnor0200h Rtu
Search vendor "Schneider-electric" for product "Modicon X80 Bmxnor0200h Rtu"
--
Safe