A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Modicon X80 BMXNOR0200H RTU SV1.70 IR22 and prior that could cause information leak concerning the current RTU configuration including communication parameters dedicated to telemetry, when a specially crafted HTTP request is sent to the web server of the module.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: schneider
Published: 2021-06-11T15:40:45
Updated: 2024-08-03T18:51:07.224Z
Reserved: 2021-01-06T00:00:00
Link: CVE-2021-22749
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-06-11T16:15:09.157
Modified: 2024-11-21T05:50:35.423
Link: CVE-2021-22749
Redhat
No data.