CyberSec.Space Logo
Back to CVE Browser

CVE-2021-22785

HIGH
7.5
CVSS Severity Score
EPSS Score0.1300%
EPSS Percentile35.69th
PublishedFeb 11, 2022
Last ModifiedMay 29, 2026

Vulnerability Description

A CWE-200: Information Exposure vulnerability exists that could cause sensitive information of files located in the web root directory to leak when an attacker sends a HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs: BMXP34 (Versions prior to V3.40), Modicon M340 X80 Ethernet Communication Modules: BMXNOE0100 (H), BMXNOE0110 (H), BMXNOC0401, BMXNOR0200H RTU (All Versions), Modicon Premium Processors with integrated Ethernet (Copro): TSXP574634, TSXP575634, TSXP576634 (All Versions), Modicon Quantum Processors with Integrated Ethernet (Copro): 140CPU65xxxxx (All Versions), Modicon Quantum Communication Modules: 140NOE771x1, 140NOC78x00, 140NOC77101 (All Versions), Modicon Premium Communication Modules: TSXETY4103, TSXETY5103 (All Versions)

Affected Platforms (CPE)

πŸ’»
Schneider Electric

Modicon M340 Bmxp342020 Firmware

< 3.40
πŸ’»
Schneider Electric

Bmxnoe0100 Firmware

All versions
πŸ’»
Schneider Electric

Bmxnoe0110 Firmware

All versions
πŸ’»
Schneider Electric

Bmxnoc0401 Firmware

All versions
πŸ’»
Schneider Electric

Bmxnor0200h Rtu Firmware

All versions
πŸ’»
Schneider Electric

Tsxp574634 Firmware

All versions
πŸ’»
Schneider Electric

Tsxp575634 Firmware

All versions
πŸ’»
Schneider Electric

Tsxp576634 Firmware

All versions
πŸ’»
Schneider Electric

140cpu65150 Firmware

All versions
πŸ’»
Schneider Electric

140noe771x1 Firmware

All versions
πŸ’»
Schneider Electric

140noc78x00 Firmware

All versions
πŸ’»
Schneider Electric

140noc77101 Firmware

All versions
πŸ’»
Schneider Electric

Tsxety4103 Firmware

All versions
πŸ’»
Schneider Electric

Tsxety5103 Firmware

All versions

References & Advisories

Related Vulnerabilities