schneider-electric Vulnerabilities and Affected Products
Vulnerabilities associated with modicon_momentum_unity_m1e_processor.
Products
Clear product- sage_44004 vulnerabilities
- struxureware_data_center_expert4 vulnerabilities
- modicon_momentum_unity_m1e_processor3 vulnerabilities
- accutech_manager2 vulnerabilities
- data_center_expert2 vulnerabilities
- easergy_studio2 vulnerabilities
- ecostruxure_it_gateway2 vulnerabilities
- modicon_m3402 vulnerabilities
- modicon_mc802 vulnerabilities
- spacelogic_as-b2 vulnerabilities
- spacelogic_as-p2 vulnerabilities
- ecostruxure_power_monitoring_expert1 vulnerability
- evlink_home_smart1 vulnerability
- foxrtu_station1 vulnerability
- modicom_m3401 vulnerability
- modicom_m340_firmware1 vulnerability
- modicon_m340_bmxp3410001 vulnerability
- modicon_m340_bmxp342030h_firmware1 vulnerability
- modicon_m580_bmeh586040s_firmware1 vulnerability
- modicon_m580_bmep585040_firmware1 vulnerability
- modicon_mc80_bmkc80203011 vulnerability
- powerlogic_pm53201 vulnerability
- powerlogic_pm53401 vulnerability
- powerlogic_pm53411 vulnerability
- t200i1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-8938CRITICAL | CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a potential arbitrary code execution after a successful Man-In-The-Middle attack followed by sending a crafted Modbus function call to tamper with memory area involved in memory size computation. CWE-119Nov 13, 2024 | CVSS9.2v4.0 | EPSS0.517% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-8935HIGH | CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss of confidentiality and integrity of controllers when conducting a Man-In-The-Middle attack between the controller and the engineering workstation while a valid user is establishing a communication session. This vulnerability is inherent to Diffie Hellman algorithm which does not protect against Man-In-The-Middle attacks. CWE-290Nov 13, 2024 | CVSS7.7v4.0 | EPSS0.483% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-8933HIGH | CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause retrieval of password hash that could lead to denial of service and loss of confidentiality and integrity of controllers. To be successful, the attacker needs to inject themself inside the logical network while a valid user uploads or downloads a project file into the controller. CWE-924Nov 13, 2024 | CVSS7.5v4.0 | EPSS0.281% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |