CVE-2021-22786

A CWE-200: Information Exposure vulnerability exists that could cause the exposure of sensitive information stored on the memory of the controller when communicating over the Modbus TCP protocol. Affected Products: Modicon M340 CPU (part numbers BMXP34*) (Versions prior to V3.30), Modicon M580 CPU (part numbers BMEP* and BMEH*) (Versions prior to SV3.20), Modicon MC80 (BMKC80) (Versions prior to V1.6), Modicon M580 CPU Safety (part numbers BMEP58*S and BMEH58*S) (All Versions), Modicon Momentum MDI (171CBU*) (Versions prior to V2.3), Legacy Modicon Quantum (All Versions)
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m340_bmxp341000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmxp341000:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m340_bmxp342000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmxp342000:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m340_bmxp342010_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmxp342010:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m340_bmxp3420102_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmxp3420102:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m340_bmxp342020_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmxp342020:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m340_bmxp342020h_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmxp342020h:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m340_bmxp342030_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmxp342030:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m340_bmxp3420302_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmxp3420302:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m340_bmxp3420302h_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmxp3420302h:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m340_bmxp342030h_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmxp342030h:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m580_bmeh582040_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m580_bmeh582040:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m580_bmeh582040c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m580_bmeh582040c:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m580_bmeh582040s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m580_bmeh582040s:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m580_bmeh584040_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m580_bmeh584040:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m580_bmeh584040c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m580_bmeh584040c:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m580_bmeh584040s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m580_bmeh584040s:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m580_bmeh586040_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m580_bmeh586040:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m580_bmeh586040c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m580_bmeh586040c:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m580_bmeh586040s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m580_bmeh586040s:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m580_bmep581020_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m580_bmep581020:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m580_bmep581020h_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m580_bmep581020h:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m580_bmep582020_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m580_bmep582020:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m580_bmep582020h_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m580_bmep582020h:-:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m580_bmep582040_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m580_bmep582040:-:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m580_bmep582040h_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m580_bmep582040h:-:*:*:*:*:*:*:*

Configuration 26 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m580_bmep582040s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m580_bmep582040s:-:*:*:*:*:*:*:*

Configuration 27 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m580_bmep583020_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m580_bmep583020:-:*:*:*:*:*:*:*

Configuration 28 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m580_bmep583040_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m580_bmep583040:-:*:*:*:*:*:*:*

Configuration 29 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m580_bmep584020_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m580_bmep584020:-:*:*:*:*:*:*:*

Configuration 30 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m580_bmep584040_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m580_bmep584040:-:*:*:*:*:*:*:*

Configuration 31 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m580_bmep584040s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m580_bmep584040s:-:*:*:*:*:*:*:*

Configuration 32 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m580_bmep585040_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m580_bmep585040:-:*:*:*:*:*:*:*

Configuration 33 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m580_bmep585040c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m580_bmep585040c:-:*:*:*:*:*:*:*

Configuration 34 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m580_bmep586040_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m580_bmep586040:-:*:*:*:*:*:*:*

Configuration 35 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m580_bmep586040c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m580_bmep586040c:-:*:*:*:*:*:*:*

Configuration 36 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_momentum_171cbu78090_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_momentum_171cbu78090:-:*:*:*:*:*:*:*

Configuration 37 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_momentum_171cbu98090_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_momentum_171cbu98090:-:*:*:*:*:*:*:*

Configuration 38 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_momentum_171cbu98091_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_momentum_171cbu98091:-:*:*:*:*:*:*:*

Configuration 39 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_mc80_bmkc8020301_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_mc80_bmkc8020301:-:*:*:*:*:*:*:*

Configuration 40 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_mc80_bmkc8020310_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_mc80_bmkc8020310:-:*:*:*:*:*:*:*

Configuration 41 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_mc80_bmkc8030311_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_mc80_bmkc8030311:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-02-01 04:15

Updated : 2024-02-28 19:51


NVD link : CVE-2021-22786

Mitre link : CVE-2021-22786

CVE.ORG link : CVE-2021-22786


JSON object : View

Products Affected

schneider-electric

  • modicon_m580_bmep581020h_firmware
  • modicon_m340_bmxp342030h_firmware
  • modicon_m340_bmxp342030
  • modicon_m580_bmep584040_firmware
  • modicon_m580_bmep582040s_firmware
  • modicon_m580_bmep582040h_firmware
  • modicon_m340_bmxp342020h_firmware
  • modicon_m580_bmep583020_firmware
  • modicon_m340_bmxp3420302_firmware
  • modicon_mc80_bmkc8020310_firmware
  • modicon_m580_bmep585040
  • modicon_m580_bmeh582040c
  • modicon_m580_bmep584040
  • modicon_momentum_171cbu98091_firmware
  • modicon_m580_bmep584040s
  • modicon_mc80_bmkc8030311
  • modicon_mc80_bmkc8020301
  • modicon_m580_bmeh584040c_firmware
  • modicon_m340_bmxp341000
  • modicon_mc80_bmkc8030311_firmware
  • modicon_m580_bmeh584040_firmware
  • modicon_m340_bmxp3420302h
  • modicon_m580_bmeh584040s
  • modicon_m580_bmep586040_firmware
  • modicon_m340_bmxp342000_firmware
  • modicon_m340_bmxp3420302
  • modicon_m340_bmxp342010
  • modicon_m340_bmxp342000
  • modicon_m580_bmeh582040s
  • modicon_m580_bmep582040
  • modicon_m580_bmep585040c
  • modicon_m580_bmeh584040s_firmware
  • modicon_m580_bmeh582040s_firmware
  • modicon_m580_bmeh584040c
  • modicon_m340_bmxp342030_firmware
  • modicon_momentum_171cbu78090_firmware
  • modicon_m580_bmep586040c_firmware
  • modicon_m580_bmep585040_firmware
  • modicon_m580_bmeh584040
  • modicon_m580_bmep581020
  • modicon_m580_bmeh586040c
  • modicon_m340_bmxp3420302h_firmware
  • modicon_m580_bmep586040
  • modicon_m580_bmep582020h
  • modicon_m580_bmeh586040c_firmware
  • modicon_momentum_171cbu98090
  • modicon_m340_bmxp342020h
  • modicon_m580_bmeh586040
  • modicon_m580_bmep583040_firmware
  • modicon_m580_bmep584020
  • modicon_m580_bmep584020_firmware
  • modicon_m580_bmep584040s_firmware
  • modicon_m580_bmeh582040c_firmware
  • modicon_m340_bmxp342020
  • modicon_m580_bmep581020h
  • modicon_m340_bmxp3420102
  • modicon_m580_bmep583040
  • modicon_m580_bmeh582040_firmware
  • modicon_m580_bmeh586040_firmware
  • modicon_m580_bmep585040c_firmware
  • modicon_m580_bmep582020_firmware
  • modicon_m580_bmep582020
  • modicon_m580_bmep586040c
  • modicon_m340_bmxp342030h
  • modicon_m340_bmxp342020_firmware
  • modicon_m580_bmep582040s
  • modicon_momentum_171cbu98091
  • modicon_m580_bmeh586040s
  • modicon_momentum_171cbu98090_firmware
  • modicon_m580_bmep582020h_firmware
  • modicon_mc80_bmkc8020301_firmware
  • modicon_m580_bmeh582040
  • modicon_m580_bmep581020_firmware
  • modicon_m580_bmep583020
  • modicon_m340_bmxp342010_firmware
  • modicon_m580_bmep582040h
  • modicon_m340_bmxp341000_firmware
  • modicon_m580_bmeh586040s_firmware
  • modicon_m580_bmep582040_firmware
  • modicon_momentum_171cbu78090
  • modicon_mc80_bmkc8020310
  • modicon_m340_bmxp3420102_firmware
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor