mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-06-19 17:31:42 +00:00
146 lines
5.2 KiB
JSON
146 lines
5.2 KiB
JSON
{
|
|
"id": "CVE-2021-22749",
|
|
"sourceIdentifier": "cybersecurity@se.com",
|
|
"published": "2021-06-11T16:15:09.157",
|
|
"lastModified": "2021-06-22T19:02:22.153",
|
|
"vulnStatus": "Analyzed",
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Modicon X80 BMXNOR0200H RTU SV1.70 IR22 and prior that could cause information leak concerning the current RTU configuration including communication parameters dedicated to telemetry, when a specially crafted HTTP request is sent to the web server of the module."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "Un CWE-787: Se presenta una vulnerabilidad de Exposici\u00f3n de Informaci\u00f3n Confidencial a un Actor No Autorizado en Modicon X80 BMXNOR0200H RTU versiones SV1.70 IR22 y anteriores, que podr\u00eda provocar un filtrado de informaci\u00f3n relativa a la configuraci\u00f3n actual de la RTU, incluidos los par\u00e1metros de comunicaci\u00f3n dedicados a la telemetr\u00eda, cuando se env\u00eda una petici\u00f3n HTTP especialmente dise\u00f1ada al servidor web del m\u00f3dulo"
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV31": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"cvssData": {
|
|
"version": "3.1",
|
|
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
|
|
"attackVector": "NETWORK",
|
|
"attackComplexity": "LOW",
|
|
"privilegesRequired": "NONE",
|
|
"userInteraction": "NONE",
|
|
"scope": "UNCHANGED",
|
|
"confidentialityImpact": "LOW",
|
|
"integrityImpact": "NONE",
|
|
"availabilityImpact": "NONE",
|
|
"baseScore": 5.3,
|
|
"baseSeverity": "MEDIUM"
|
|
},
|
|
"exploitabilityScore": 3.9,
|
|
"impactScore": 1.4
|
|
}
|
|
],
|
|
"cvssMetricV2": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"cvssData": {
|
|
"version": "2.0",
|
|
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
|
|
"accessVector": "NETWORK",
|
|
"accessComplexity": "LOW",
|
|
"authentication": "NONE",
|
|
"confidentialityImpact": "PARTIAL",
|
|
"integrityImpact": "NONE",
|
|
"availabilityImpact": "NONE",
|
|
"baseScore": 5.0
|
|
},
|
|
"baseSeverity": "MEDIUM",
|
|
"exploitabilityScore": 10.0,
|
|
"impactScore": 2.9,
|
|
"acInsufInfo": false,
|
|
"obtainAllPrivilege": false,
|
|
"obtainUserPrivilege": false,
|
|
"obtainOtherPrivilege": false,
|
|
"userInteractionRequired": false
|
|
}
|
|
]
|
|
},
|
|
"weaknesses": [
|
|
{
|
|
"source": "cybersecurity@se.com",
|
|
"type": "Primary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-200"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"configurations": [
|
|
{
|
|
"operator": "AND",
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:schneider-electric:modicon_x80_bmxnor0200h_rtu:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "B59B3372-5D62-469D-92C1-368788CC98DE"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:schneider-electric:modicon_x80_bmxnor0200h_rtu_firmware:sv1.6:ir4:*:*:*:*:*:*",
|
|
"matchCriteriaId": "8841CE06-FD95-41E4-A5FB-A83B9F2BD558"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:schneider-electric:modicon_x80_bmxnor0200h_rtu_firmware:sv1.7:ir10:*:*:*:*:*:*",
|
|
"matchCriteriaId": "D02244CF-75D7-4952-9344-F72F9A70DE3C"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:schneider-electric:modicon_x80_bmxnor0200h_rtu_firmware:sv1.7:ir15b:*:*:*:*:*:*",
|
|
"matchCriteriaId": "ED3E913A-4A96-4AB5-9EDC-4E56F0735B2A"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:schneider-electric:modicon_x80_bmxnor0200h_rtu_firmware:sv1.7:ir17:*:*:*:*:*:*",
|
|
"matchCriteriaId": "5F5B0DA3-9E61-4F30-A38E-EB444FA5C914"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:schneider-electric:modicon_x80_bmxnor0200h_rtu_firmware:sv1.7:ir18:*:*:*:*:*:*",
|
|
"matchCriteriaId": "72E56D0A-9A04-462B-BDFD-C5852C79C46B"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:schneider-electric:modicon_x80_bmxnor0200h_rtu_firmware:sv1.7:ir19:*:*:*:*:*:*",
|
|
"matchCriteriaId": "66DF481E-4B26-4F19-AD1E-D063756D9016"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:schneider-electric:modicon_x80_bmxnor0200h_rtu_firmware:sv1.7:ir20:*:*:*:*:*:*",
|
|
"matchCriteriaId": "A3AAC25B-BD85-47C5-9E58-B603670581A1"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-05",
|
|
"source": "cybersecurity@se.com",
|
|
"tags": [
|
|
"Vendor Advisory"
|
|
]
|
|
}
|
|
]
|
|
} |