Unrated severityNVD Advisory· Published Nov 22, 2022· Updated Apr 28, 2025
CVE-2022-37301
CVE-2022-37301
Description
A CWE-191: Integer Underflow (Wrap or Wraparound) vulnerability exists that could cause a denial of service of the controller due to memory access violations when using the Modbus TCP protocol. Affected products: Modicon M340 CPU (part numbers BMXP34*)(V3.40 and prior), Modicon M580 CPU (part numbers BMEP* and BMEH*)(V3.22 and prior), Legacy Modicon Quantum/Premium(All Versions), Modicon Momentum MDI (171CBU*)(All Versions), Modicon MC80 (BMKC80)(V1.7 and prior)
Affected products
8- Range: <=V3.22
<=V1.7+ 1 more
- (no CPE)range: <=V1.7
- (no CPE)range: V
- Range: <=V3.40
- Schneider Electric/Legacy Modicon Quantum/Premiumv5Range: All Versions
- Schneider Electric/Modicon M340 CPU (part numbers BMXP34*)v5Range: V
- Schneider Electric/Modicon M580 CPU (part numbers BMEP* and BMEH*)v5Range: V
- Schneider Electric/Modicon Momentum MDI (171CBU*)v5Range: All Versions
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.