VYPR
Unrated severityNVD Advisory· Published Nov 22, 2022· Updated Apr 28, 2025

CVE-2022-37301

CVE-2022-37301

Description

A CWE-191: Integer Underflow (Wrap or Wraparound) vulnerability exists that could cause a denial of service of the controller due to memory access violations when using the Modbus TCP protocol. Affected products: Modicon M340 CPU (part numbers BMXP34*)(V3.40 and prior), Modicon M580 CPU (part numbers BMEP* and BMEH*)(V3.22 and prior), Legacy Modicon Quantum/Premium(All Versions), Modicon Momentum MDI (171CBU*)(All Versions), Modicon MC80 (BMKC80)(V1.7 and prior)

Affected products

8
  • Range: <=V3.22
  • Schneider Electric/Modicon MC80llm-create2 versions
    <=V1.7+ 1 more
    • (no CPE)range: <=V1.7
    • (no CPE)range: V
  • Range: <=V3.40
  • Schneider Electric/Legacy Modicon Quantum/Premiumv5
    Range: All Versions
  • Schneider Electric/Modicon M340 CPU (part numbers BMXP34*)v5
    Range: V
  • Schneider Electric/Modicon M580 CPU (part numbers BMEP* and BMEH*)v5
    Range: V
  • Schneider Electric/Modicon Momentum MDI (171CBU*)v5
    Range: All Versions

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.