Vulnerabilities > Schneider Electric > Modicon M580 Bmep586040 Firmware

DATE CVE VULNERABILITY TITLE RISK
2023-02-01 CVE-2021-22786 Unspecified vulnerability in Schneider-Electric products
A CWE-200: Information Exposure vulnerability exists that could cause the exposure of sensitive information stored on the memory of the controller when communicating over the Modbus TCP protocol.
network
low complexity
schneider-electric
7.5
2023-01-31 CVE-2022-45789 Unspecified vulnerability in Schneider-Electric products
A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session.
network
low complexity
schneider-electric
critical
9.8
2023-01-30 CVE-2022-45788 Unspecified vulnerability in Schneider-Electric products
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when a malicious project file is loaded onto the controller.
network
low complexity
schneider-electric
critical
9.8
2022-11-22 CVE-2022-37301 Unspecified vulnerability in Schneider-Electric products
A CWE-191: Integer Underflow (Wrap or Wraparound) vulnerability exists that could cause a denial of service of the controller due to memory access violations when using the Modbus TCP protocol.
network
low complexity
schneider-electric
7.5
2022-09-12 CVE-2022-37300 Unspecified vulnerability in Schneider-Electric products
A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communicating over Modbus.
network
low complexity
schneider-electric
critical
9.8
2021-07-14 CVE-2021-22779 Unspecified vulnerability in Schneider-Electric products
Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Control Expert V15.0 SP1, EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), SCADAPack RemoteConnect for x70 (all versions), Modicon M580 CPU (all versions - part numbers BMEP* and BMEH*), Modicon M340 CPU (all versions - part numbers BMXP34*), that could cause unauthorized access in read and write mode to the controller by spoofing the Modbus communication between the engineering software and the controller.
network
low complexity
schneider-electric
critical
9.1
2020-12-11 CVE-2020-7543 Unspecified vulnerability in Schneider-Electric products
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum & Modicon Premium (see security notifications for affected versions), that could cause denial of service when a specially crafted Read Physical Memory request over Modbus is sent to the controller.
network
low complexity
schneider-electric
7.5
2020-12-11 CVE-2020-7542 Unspecified vulnerability in Schneider-Electric products
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum & Modicon Premium (see security notifications for affected versions), that could cause denial of service when a specially crafted Read Physical Memory request over Modbus is sent to the controller.
network
low complexity
schneider-electric
7.5
2020-12-11 CVE-2020-7537 Unspecified vulnerability in Schneider-Electric products
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum & Modicon Premium (see security notifications for affected versions), that could cause denial of service when a specially crafted Read Physical Memory request over Modbus is sent to the controller.
network
low complexity
schneider-electric
7.5
2020-01-06 CVE-2019-6855 Incorrect Authorization vulnerability in Schneider-Electric products
Incorrect Authorization vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20) , and Modicon M580 (all versions prior to V3.10), which could cause a bypass of the authentication process between EcoStruxure Control Expert and the M340 and M580 controllers.
network
low complexity
schneider-electric CWE-863
7.3