Medium severity5.5NVD Advisory· Published Jul 13, 2022· Updated Jun 17, 2026
CVE-2022-34765
CVE-2022-34765
Description
A CWE-73: External Control of File Name or Path vulnerability exists that could cause loading of unauthorized firmware images when user-controlled data is written to the file path. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)
Affected products
6- cpe:2.3:o:schneider-electric:opc_ua_module_for_m580_firmware:*:*:*:*:*:*:*:*Range: <=1.10
- cpe:2.3:o:schneider-electric:x80_advanced_rtu_module_firmware:*:*:*:*:*:*:*:*Range: >=2.01
- Range: <=1.10
>=2.01+ 1 more
- (no CPE)range: >=2.01
- (no CPE)range: V2.01
- Range: BMENUA0100
Patches
Vulnerability mechanics
References
1- download.schneider-electric.com/filesnvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.