Security News > 2021 > July > Critical vulnerability in Schneider Electric Modicon PLCs can lead to RCE (CVE-2021-22779)

Researchers at Armis discovered an authentication bypass vulnerability in Schneider Electric's Modicon programmable logic controllers that can lead to remote-code-execution.
Modicon M580. The vulnerability, dubbed ModiPwn, allows for a complete takeover of impacted devices by leveraging the UMAS protocol, and impacts Modicon M340, M580 and other models from the Modicon series.
An attack that leverages ModiPwn would begin with network access to a Modicon PLC. Through this access, the attacker can leverage undocumented commands in the UMAS protocol and leak a certain hash from the device's memory.
This will allow the attacker to abuse additional undocumented commands that lead to remote-code-execution - a full takeover of the device.
Sophisticated attacks such as this have been seen in the wild before; the Triton malware, for example, was spotted targeting safety controllers by Schneider Electric used in petrochemical plants in Saudi Arabia.
"The trouble with these legacy devices found in OT environments is that historically, they have evolved over unencrypted protocols. It will take time to address these weak underlying protocols. In the meantime, organizations operating in these environments should ensure that they have visibility over these devices to see where their points of exposure lie. This is crucial to preventing attackers from being able to control their systems - or even hold them to ransom," Seri concluded.
News URL
http://feedproxy.google.com/~r/HelpNetSecurity/~3/AjzUz6Qr89Q/
Related news
- Gladinet’s Triofox and CentreStack Under Active Exploitation via Critical RCE Vulnerability (source)
- Critical Commvault RCE vulnerability fixed, PoC available (CVE-2025-34028) (source)
- Critical Apache Roller Vulnerability (CVSS 10.0) Enables Unauthorized Session Persistence (source)
- Critical Erlang/OTP SSH Vulnerability (CVSS 10.0) Allows Unauthenticated Code Execution (source)
- Critical Erlang/OTP SSH pre-auth RCE is 'Surprisingly Easy' to exploit, patch now (source)
- Critical Erlang/OTP SSH RCE bug now has public exploits, patch now (source)
- Critical Langflow RCE flaw exploited to hack AI app servers (source)
- SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version (source)
- Unpatched critical bugs in Versa Concerto lead to auth bypass, RCE (source)
- Critical Windows Server 2025 dMSA Vulnerability Enables Active Directory Compromise (source)