CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel
Published Nov 13, 2024
7.5
HIGHCVSS 4.0
EPSS 0.29%
Description
CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause retrieval of password hash that could lead to denial of service and loss of confidentiality and integrity of controllers. To be successful, the attacker needs to inject themself inside the logical network while a valid user uploads or downloads a project file into the controller.
Affected products
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All VersionsStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Schneider Electric | Modicon M340 CPU (part numbers BMXP34*) | unaffected |
| ||||||
| Schneider Electric | Modicon MC80 (part numbers BMKC80) | unaffected |
| ||||||
| Schneider Electric | Modicon Momentum Unity M1E Processor (171CBU*) | unaffected |
|
No data.
-
- Version 0StatusaffectedConstraints<*
- Version
-
- Version 0StatusaffectedConstraints<*
- Version
-
- Version 0StatusaffectedConstraints<*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Schneider Electric | Modicon M340 | n/a |
| ||||||
| Schneider Electric | Modicon Mc80 | n/a |
| ||||||
| Schneider Electric | Modicon Momentum Unity M1e Processor | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (1)
Change history (0)
No recorded changes yet.