CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss
Published Nov 13, 2024
7.7
HIGHCVSS 4.0
EPSS 0.50%
Description
CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss of confidentiality and integrity of controllers when conducting a Man-In-The-Middle attack between the controller and the engineering workstation while a valid user is establishing a communication session. This vulnerability is inherent to Diffie Hellman algorithm which does not protect against Man-In-The-Middle attacks.
Affected products
-
- Version All versions since SV3.60StatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All VersionsStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Schneider Electric | Modicon M340 CPU (part numbers BMXP34*) | unaffected |
| ||||||
| Schneider Electric | Modicon MC80 (part numbers BMKC80) | unaffected |
| ||||||
| Schneider Electric | Modicon Momentum Unity M1E Processor (171CBU*) | unaffected |
|
No data.
-
- Version SV3.60StatusaffectedConstraints<*
- Version
-
- Version 0StatusaffectedConstraints<*
- Version
-
- Version 0StatusaffectedConstraints<*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Schneider Electric | Modicon M340 Bmxp341000 | n/a |
| ||||||
| Schneider Electric | Modicon Mc80 Bmkc8020301 | n/a |
| ||||||
| Schneider Electric | Modicon Momentum Unity M1e Processor | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
Change history (0)
No recorded changes yet.