A CWE-73: External Control of File Name or Path vulnerability exists that could cause loading of unauthorized firmware images when user-controlled data is written to the file path. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)
2022-07-13T21:15:08.800
2024-11-21T07:10:08.640
Modified
CVSSv3.1: 5.5 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | schneider-electric | opc_ua_module_for_m580_firmware | ≤ 1.10 | Yes |
| Hardware | schneider-electric | opc_ua_module_for_m580 | - | No |
| Operating System | schneider-electric | x80_advanced_rtu_module_firmware | ≥ 2.01 | Yes |
| Hardware | schneider-electric | x80_advanced_rtu_module | - | No |