VDB

CVE-2024-8937

CVE-2024-8937 PUBLISHED CVSS 8.300000190734863 HIGH

CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a potential arbitrary code execution after a successful Man-In-The Middle attack followed by sending a crafted Modbus function call to tamper with memory area involved in the authentication process.

EPSS 0.08% · 24.7th percentile

Risk Scores

CVSS 4.0
8.300000190734863
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS Score
0.08%
24.7th percentile

Affected Products

VendorProductVersions
Schneider ElectricModicon Momentum Unity M1E Processor (171CBU*)All Versions
Schneider ElectricModicon M340 CPU (part numbers BMXP34*)Versions prior to SV3.65
Schneider ElectricModicon MC80 (part numbers BMKC80)All versions

Timeline

  • Nov 12, 2024 CVE Published
  • Nov 13, 2024 EPSS Score
  • Nov 13, 2024 Coalition ESS Score
  • Nov 13, 2024 Coalition ESS Score
  • Nov 13, 2024 PoC Published
  • Nov 21, 2024 PoC Published
  • Nov 22, 2024 PoC Published
  • Dec 2, 2024 EPSS Score
  • Dec 19, 2024 EPSS Score
  • Jan 6, 2025 EPSS Score
  • Jan 24, 2025 EPSS Score
  • Feb 10, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›