Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c7w2-f8m6-pxp8

Опубликовано: 06 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session. Affected Products: EcoStruxure™ Control Expert (All Versions), EcoStruxure™ Process Expert (Version V2020 & prior), Modicon M340 CPU (part numbers BMXP34*) (All Versions), Modicon M580 CPU (part numbers BMEP* and BMEH*) (All Versions), Modicon M580 CPU Safety (part numbers BMEP58S and BMEH58S) (All Versions)

A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session. Affected Products: EcoStruxure™ Control Expert (All Versions), EcoStruxure™ Process Expert (Version V2020 & prior), Modicon M340 CPU (part numbers BMXP34*) (All Versions), Modicon M580 CPU (part numbers BMEP* and BMEH*) (All Versions), Modicon M580 CPU Safety (part numbers BMEP58S and BMEH58S) (All Versions)

EPSS

Процентиль: 24%
0.00083
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-294

Связанные уязвимости

CVSS3: 8.1
nvd
около 3 лет назад

A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session. Affected Products: EcoStruxure Control Expert (All Versions), EcoStruxure Process Expert (All Versions), Modicon M340 CPU - part numbers BMXP34* (All Versions), Modicon M580 CPU - part numbers BMEP* and BMEH* (All Versions), Modicon M580 CPU Safety - part numbers BMEP58*S and BMEH58*S (All Versions)

CVSS3: 8.1
fstec
около 3 лет назад

Уязвимость системы автоматизации технологических процессов EcoStruxure Process Expert, связанная с обходом процедуры аутентификации, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 24%
0.00083
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-294