CVE-2022-34763 MEDIUM

CVE-2022-34763

Vendor Schneider Electric
Product OPC UA Modicon Communication Module
Weakness CWE-345
Published July 13, 2022
Last update September 16, 2024

CVSS base score

5.9/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H

What the vulnerability does

01Description

A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists that could cause loading of unauthorized firmware images due to improper verification of the firmware signature. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)

Key dates

02Disclosure timeline

July 13, 2022 CVE published
September 16, 2024 Record updated