Security readout for executives and security teams
Plain-English summary
This flaw can let an unauthenticated network user read sensitive information from affected Schneider Electric Modicon controller memory over Modbus TCP. It is a confidentiality issue, not described as code execution or outage. Business urgency is highest where affected controllers are reachable from untrusted networks or support safety or operational processes.
Executive priority
Treat as a high-priority OT confidentiality exposure. It does not indicate immediate process disruption, but exposed controller memory can reveal sensitive operational information. Prioritize internet- or partner-reachable controllers and all-version affected legacy or safety systems.
Technical view
CVE-2021-22786 is CWE-200 information exposure in Schneider Electric Modicon controllers using Modbus TCP. CVSS 3.1 is 7.5: network reachable, low complexity, no privileges, no user interaction, high confidentiality impact, no stated integrity or availability impact.
Likely exposure
Exposure depends on whether affected Modicon M340, M580, MC80, M580 Safety, Momentum 171CBU, or legacy Quantum controllers are deployed and reachable over Modbus TCP. The source identifies fixed-version thresholds for several product lines, while M580 Safety and legacy Quantum are listed as all versions affected.
Exploitation context
The provided sources do not state active exploitation, public exploit availability, or CISA KEV listing. The risk comes from unauthenticated network reachability and the possibility of disclosing sensitive controller memory through normal protocol communication paths.
Researcher notes
Evidence is limited to the CVE record and Schneider advisory reference. Do not assume integrity or availability impact beyond the CVSS vector. Validate exposure through asset inventory, firmware comparison, and network reachability rather than exploit testing.
Mitigation direction
- Review Schneider Electric SEVD-2022-221-04 for product-specific remediation guidance.
- Upgrade M340 CPUs to V3.30 or later where applicable.
- Upgrade M580 CPUs to SV3.20 or later where applicable.
- Upgrade MC80 to V1.6 or later where applicable.
- Upgrade Momentum 171CBU products to V2.3 or later where applicable.
- For all-version affected products, obtain Schneider guidance on compensating controls or replacement.
Validation and detection
- Inventory Modicon controllers and record exact model, part number, and firmware version.
- Confirm whether Modbus TCP is reachable from untrusted or routable networks.
- Compare firmware against affected thresholds in the Schneider advisory and CVE record.
- Prioritize validation for safety, production-critical, and legacy Quantum deployments.
- Document any all-version affected assets awaiting vendor-approved remediation.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-200: Information exposure and cloud metadata lookup
Information exposure and SSRF weaknesses can make discovery, cloud metadata, and credential material review relevant. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2021-22786 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- High
- CVSS
- 7.5 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N3.93.6Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
7.5HighVector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Exposure of Sensitive Information to an Unauthorized Actor
Exposure of Sensitive Information to an Unauthorized Actor represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
