LiveActive security incident?Get immediate response
CVE Record

CVE-2021-22786: A CWE-200: Information Exposure vulnerability exists that could cause the exposure of sensitive information...

A CWE-200: Information Exposure vulnerability exists that could cause the exposure of sensitive information stored on the memory of the controller when communicating over the Modbus TCP protocol. Affected Products: Modicon M340 CPU (part numbers BMXP34*) (Versions prior to V3.30), Modicon M580 CPU (part numbers BMEP* and BMEH*) (Versions prior to SV3.20), Modicon MC80 (BMKC80) (Versions prior to V1.6), Modicon M580 CPU Safety (part numbers BMEP58*S and BMEH58*S) (All Versions), Modicon Momentum MDI (171CBU*) (Versions prior to V2.3), Legacy Modicon Quantum (All Versions)

HighCVSS 7.5Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

This flaw can let an unauthenticated network user read sensitive information from affected Schneider Electric Modicon controller memory over Modbus TCP. It is a confidentiality issue, not described as code execution or outage. Business urgency is highest where affected controllers are reachable from untrusted networks or support safety or operational processes.

Executive priority

Treat as a high-priority OT confidentiality exposure. It does not indicate immediate process disruption, but exposed controller memory can reveal sensitive operational information. Prioritize internet- or partner-reachable controllers and all-version affected legacy or safety systems.

Technical view

CVE-2021-22786 is CWE-200 information exposure in Schneider Electric Modicon controllers using Modbus TCP. CVSS 3.1 is 7.5: network reachable, low complexity, no privileges, no user interaction, high confidentiality impact, no stated integrity or availability impact.

Likely exposure

Exposure depends on whether affected Modicon M340, M580, MC80, M580 Safety, Momentum 171CBU, or legacy Quantum controllers are deployed and reachable over Modbus TCP. The source identifies fixed-version thresholds for several product lines, while M580 Safety and legacy Quantum are listed as all versions affected.

Exploitation context

The provided sources do not state active exploitation, public exploit availability, or CISA KEV listing. The risk comes from unauthenticated network reachability and the possibility of disclosing sensitive controller memory through normal protocol communication paths.

Researcher notes

Evidence is limited to the CVE record and Schneider advisory reference. Do not assume integrity or availability impact beyond the CVSS vector. Validate exposure through asset inventory, firmware comparison, and network reachability rather than exploit testing.

Mitigation direction

  • Review Schneider Electric SEVD-2022-221-04 for product-specific remediation guidance.
  • Upgrade M340 CPUs to V3.30 or later where applicable.
  • Upgrade M580 CPUs to SV3.20 or later where applicable.
  • Upgrade MC80 to V1.6 or later where applicable.
  • Upgrade Momentum 171CBU products to V2.3 or later where applicable.
  • For all-version affected products, obtain Schneider guidance on compensating controls or replacement.

Validation and detection

  • Inventory Modicon controllers and record exact model, part number, and firmware version.
  • Confirm whether Modbus TCP is reachable from untrusted or routable networks.
  • Compare firmware against affected thresholds in the Schneider advisory and CVE record.
  • Prioritize validation for safety, production-critical, and legacy Quantum deployments.
  • Document any all-version affected assets awaiting vendor-approved remediation.
Prepared
Confidence
high
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-200: Information exposure and cloud metadata lookup

Information exposure and SSRF weaknesses can make discovery, cloud metadata, and credential material review relevant. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2021-22786 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
7.5 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
7.5CVSS 3.1HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N3.93.6Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

7.5High
CVSS 3.1 vector shape for CVE-2021-22786Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Schneider ElectricModicon M340 CPU (part numbers BMXP34*)AllListed
Schneider ElectricModicon M580 CPU (part numbers BMEP* and BMEH*)AllListed
Schneider ElectricModicon M580 CPU Safety (part numbers BMEP58*S and BMEH58*S)All VersionsListed
Schneider ElectricModicon MC80 (BMKC80)AllListed
Schneider ElectricModicon Momentum CPU (171CBU*)AllListed
Schneider ElectricLegacy Modicon QuantumAll VersionsListed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-200 · source CWE mapping

Exposure of Sensitive Information to an Unauthorized Actor

Exposure of Sensitive Information to an Unauthorized Actor represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.