VDB

CVE-2024-8936

CVE-2024-8936 PUBLISHED CVSS 8.300000190734863 HIGH

CWE-20: Improper Input Validation vulnerability exists that could lead to loss of confidentiality of controller memory after a successful Man-In-The-Middle attack followed by sending a crafted Modbus function call used to tamper with memory.

EPSS 0.08% · 23.7th percentile

Risk Scores

CVSS 4.0
8.300000190734863
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS Score
0.08%
23.7th percentile

Affected Products

VendorProductVersions
Schneider ElectricModicon M340 CPU (part numbers BMXP34*)Versions prior to SV3.65

Timeline

  • Nov 12, 2024 CVE Published
  • Nov 13, 2024 EPSS Score
  • Nov 13, 2024 Coalition ESS Score
  • Nov 13, 2024 Coalition ESS Score
  • Nov 13, 2024 PoC Published
  • Nov 13, 2024 PoC Published
  • Nov 13, 2024 CVE Updated
  • Nov 21, 2024 PoC Published
  • Dec 2, 2024 EPSS Score
  • Dec 19, 2024 EPSS Score
  • Jan 6, 2025 EPSS Score
  • Jan 24, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›