Versio.io

CVE-2021-22816

Common vulnerabilities & exposures (CVE)

CVE databaseCVE database blogpostRelease & EoL database
 
Published at: - 28-01-2022 09:15
Last modified: - 03-02-2022 02:31
Total changes: - 3

Description

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause a Denial of Service of the RTU when receiving a specially crafted request over Modbus, and the RTU is configured as a Modbus server. Affected Products: SCADAPack 312E, 313E, 314E, 330E, 333E, 334E, 337E, 350E and 357E RTUs with firmware V8.18.1 and prior

Common Vulnerability Scoring System (CVSS)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Low
Attack complexity
Network
Attack vector
High
Availability
None
Confidentiality
None
Integrity
None
Privileges required
Unchanged
Scope
None
User interaction
7.5
Base score
3.9
3.6
Exploitability score
Impact score
 

Verification logic

OR
AND
OR
vendor=schneider-electric AND product=scadapack_312e_firmware AND versionEndExcluding=8.19.1
OR
vendor=schneider-electric AND product=scadapack_312e AND version=-
AND
OR
vendor=schneider-electric AND product=scadapack_313e_firmware AND versionEndExcluding=8.19.1
OR
vendor=schneider-electric AND product=scadapack_313e AND version=-
AND
OR
vendor=schneider-electric AND product=scadapack_314e_firmware AND versionEndExcluding=8.19.1
OR
vendor=schneider-electric AND product=scadapack_314e AND version=-
AND
OR
vendor=schneider-electric AND product=scadapack_330e_firmware AND versionEndExcluding=8.19.1
OR
vendor=schneider-electric AND product=scadapack_330e AND version=-
AND
OR
vendor=schneider-electric AND product=scadapack_333e_firmware AND versionEndExcluding=8.19.1
OR
vendor=schneider-electric AND product=scadapack_333e AND version=-
AND
OR
vendor=schneider-electric AND product=scadapack_334e_firmware AND versionEndExcluding=8.19.1
OR
vendor=schneider-electric AND product=scadapack_334e AND version=-
AND
OR
vendor=schneider-electric AND product=scadapack_337e_firmware AND versionEndExcluding=8.19.1
OR
vendor=schneider-electric AND product=scadapack_337e AND version=-
AND
OR
vendor=schneider-electric AND product=scadapack_350e_firmware AND versionEndExcluding=8.19.1
OR
vendor=schneider-electric AND product=scadapack_350e AND version=-
AND
OR
vendor=schneider-electric AND product=scadapack_357e_firmware AND versionEndExcluding=8.19.1
OR
vendor=schneider-electric AND product=scadapack_357e AND version=-
 

Reference

 


Keywords

NVD

 

CVE-2021-22816

 

CVE

 

Common vulnerabilities & exposures

 

CVSS

 

Common vulnerability scoring system

 

Security

 

Vulnerabilities

 

Exposures

 

We use cookies to ensure that we give you the best experience on our website. Read privacy policies for more information.