VDB
CVE-2024-8936
CVE-2024-8936
PUBLISHED
CVSS 8.300000190734863 HIGH
CWE-20: Improper Input Validation vulnerability exists that could lead to loss of confidentiality of controller memory after a successful Man-In-The-Middle attack followed by sending a crafted Modbus function call used to tamper with memory.
EPSS 0.08% · 23.7th percentile
Risk Scores
CVSS 4.0
8.300000190734863
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS Score
0.08%
23.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider Electric | Modicon M340 CPU (part numbers BMXP34*) | Versions prior to SV3.65 |
Exploit Intelligence
- CIRCL seen: CVE-2024-8936 (circl-sighting)
- CIRCL seen: CVE-2024-8936 (circl-sighting)
- CIRCL seen: CVE-2024-8936 (circl-sighting)
- https://download.schneider-electric.com/doc/SEVD-2024-317-03/SEVD-2024-317-03.pdf (circl)
Timeline
- Nov 12, 2024 CVE Published
- Nov 13, 2024 EPSS Score
- Nov 13, 2024 Coalition ESS Score
- Nov 13, 2024 Coalition ESS Score
- Nov 13, 2024 PoC Published
- Nov 13, 2024 PoC Published
- Nov 13, 2024 CVE Updated
- Nov 21, 2024 PoC Published
- Dec 2, 2024 EPSS Score
- Dec 19, 2024 EPSS Score
- Jan 6, 2025 EPSS Score
- Jan 24, 2025 EPSS Score
References
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-317-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-317-04.pdf advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-317-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-317-02.pdf advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-317-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-317-03.pdf advisory
- https://download.schneider-electric.com/doc/SEVD-2024-317-03/SEVD-2024-317-03.pdf url
- https://nvd.nist.gov/vuln/detail/CVE-2024-8936 advisory