A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause unauthorized firmware image loading when unsigned images are added to the firmware image path. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)
2022-07-13T21:15:08.633
2024-11-21T07:10:08.287
Modified
CVSSv3.1: 5.9 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | schneider-electric | opc_ua_module_for_m580_firmware | ≤ 1.10 | Yes |
Hardware | schneider-electric | opc_ua_module_for_m580 | - | No |
Operating System | schneider-electric | x80_advanced_rtu_module_firmware | ≥ 2.01 | Yes |
Hardware | schneider-electric | x80_advanced_rtu_module | - | No |