Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-34765


A CWE-73: External Control of File Name or Path vulnerability exists that could cause loading of unauthorized firmware images when user-controlled data is written to the file path. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)


Published

2022-07-13T21:15:08.800

Last Modified

2024-11-21T07:10:08.640

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-73
  • Type: Primary
    CWE-668

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System schneider-electric opc_ua_module_for_m580_firmware ≤ 1.10 Yes
Hardware schneider-electric opc_ua_module_for_m580 - No
Operating System schneider-electric x80_advanced_rtu_module_firmware ≥ 2.01 Yes
Hardware schneider-electric x80_advanced_rtu_module - No

References