A CWE-476: NULL Pointer Dereference vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all versions), Modicon MC80 (part numbers BMKC80*, all versions), Modicon Momentum Ethernet CPU (part numbers 171CBU*, all versions), PLC Simulator for EcoStruxureª Control Expert, including all Unity Pro versions (former name of EcoStruxureª Control Expert, all versions), PLC Simulator for EcoStruxureª Process Expert including all HDCS versions (former name of EcoStruxureª Process Expert, all versions), Modicon Quantum CPU (part numbers 140CPU*, all versions), Modicon Premium CPU (part numbers TSXP5*, all versions).
Project Subscriptions
| Vendors | Products |
|---|---|
|
Schneider-electric
Subscribe
|
Modicon M340 Bmxp341000
Subscribe
Modicon M340 Bmxp342010
Subscribe
Modicon M340 Bmxp342020
Subscribe
Modicon M340 Bmxp342030
Subscribe
Modicon M580 Bmeh582040
Subscribe
Modicon M580 Bmeh582040c
Subscribe
Modicon M580 Bmeh582040s
Subscribe
Modicon M580 Bmeh584040
Subscribe
Modicon M580 Bmeh584040c
Subscribe
Modicon M580 Bmeh584040s
Subscribe
Modicon M580 Bmeh586040
Subscribe
Modicon M580 Bmeh586040c
Subscribe
Modicon M580 Bmeh586040s
Subscribe
Modicon M580 Bmep581020
Subscribe
Modicon M580 Bmep581020h
Subscribe
Modicon M580 Bmep582020
Subscribe
Modicon M580 Bmep582020h
Subscribe
Modicon M580 Bmep582040
Subscribe
Modicon M580 Bmep582040h
Subscribe
Modicon M580 Bmep582040s
Subscribe
Modicon M580 Bmep583020
Subscribe
Modicon M580 Bmep583040
Subscribe
Modicon M580 Bmep584020
Subscribe
Modicon M580 Bmep584040
Subscribe
Modicon M580 Bmep584040s
Subscribe
Modicon M580 Bmep585040
Subscribe
Modicon M580 Bmep585040c
Subscribe
Modicon M580 Bmep586040
Subscribe
Modicon M580 Bmep586040c
Subscribe
Modicon Mc80 Bmkc8020301
Subscribe
Modicon Mc80 Bmkc8020310
Subscribe
Modicon Mc80 Bmkc8030311
Subscribe
Modicon Momentum 171cbu78090
Subscribe
Modicon Momentum 171cbu98090
Subscribe
Modicon Momentum 171cbu98091
Subscribe
Modicon Premium Tsxp57 1634m
Subscribe
Modicon Premium Tsxp57 2634m
Subscribe
Modicon Premium Tsxp57 2834m
Subscribe
Modicon Premium Tsxp57 454m
Subscribe
Modicon Premium Tsxp57 4634m
Subscribe
Modicon Premium Tsxp57 554m
Subscribe
Modicon Premium Tsxp57 5634m
Subscribe
Modicon Premium Tsxp57 6634m
Subscribe
Modicon Quantum 140cpu65150
Subscribe
Modicon Quantum 140cpu65150c
Subscribe
Modicon Quantum 140cpu65160
Subscribe
Modicon Quantum 140cpu65160c
Subscribe
Plc Simulator For Ecostruxure Control Expert
Subscribe
Plc Simulator For Ecostruxure Process Expert
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-9927 | A CWE-476: NULL Pointer Dereference vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all versions), Modicon MC80 (part numbers BMKC80*, all versions), Modicon Momentum Ethernet CPU (part numbers 171CBU*, all versions), PLC Simulator for EcoStruxureª Control Expert, including all Unity Pro versions (former name of EcoStruxureª Control Expert, all versions), PLC Simulator for EcoStruxureª Process Expert including all HDCS versions (former name of EcoStruxureª Process Expert, all versions), Modicon Quantum CPU (part numbers 140CPU*, all versions), Modicon Premium CPU (part numbers TSXP5*, all versions). |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: schneider
Published:
Updated: 2024-08-03T18:51:07.455Z
Reserved: 2021-01-06T00:00:00
Link: CVE-2021-22792
No data.
Status : Modified
Published: 2021-09-02T17:15:08.343
Modified: 2024-11-21T05:50:40.770
Link: CVE-2021-22792
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD