CVE-2021-22745
Estado: ModificadaBaja (3.9)—
Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position. This CVE ID is unique from CVE-2021-22742, CVE-2021-22744, CVE-2021-22746, and CVE-2021-22747.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 3.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.25%
- Percentil entre todas las CVEs puntuadas: 14
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-754
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-22745",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.1,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.9,
"attackVector": "PHYSICAL",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 0.3
}
]
},
"affected": [
{
"source": "cybersecurity@se.com",
"affectedData": [
{
"vendor": "n/a",
"product": "Triconex Model 3009 MP installed on Tricon V11.3.x systems",
"versions": [
{
"status": "affected",
"version": "Triconex Model 3009 MP installed on Tricon V11.3.x systems"
}
]
}
]
}
],
"published": "2021-05-26T20:15:09.390",
"references": [
{
"url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-130-03",
"tags": [
"Vendor Advisory"
],
"source": "cybersecurity@se.com"
},
{
"url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-130-03",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cybersecurity@se.com",
"description": [
{
"lang": "en",
"value": "CWE-754"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position. This CVE ID is unique from CVE-2021-22742, CVE-2021-22744, CVE-2021-22746, and CVE-2021-22747."
},
{
"lang": "es",
"value": "Se presenta una vulnerabilidad de comprobación Inapropiada de Condiciones Inusuales o Excepcionales en Triconex Model 3009 MP instalado en sistemas Tricon versión V11.3.x que podría causar el reinicio del módulo cuando el TCM recibe paquetes TriStation malformados mientras el interruptor de llave de protección contra escritura está en la posición de programa. Este ID de CVE es diferente de CVE-2021-22742, CVE-2021-22744, CVE-2021-22746 y CVE-2021-22747"
}
],
"lastModified": "2026-06-17T03:37:41.863",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:schneider-electric:triconex_model_3009_mp_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "507557DF-0EBA-4203-8F5C-924E4EEEF29F",
"versionEndExcluding": "11.8.0",
"versionStartIncluding": "11.3.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:schneider-electric:triconex_model_3009_mp:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9AD3F98C-C157-4737-A1B8-CC13252E7D24"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:schneider-electric:tcm_4351b_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E12A07EB-7CF9-4CB1-AAFE-D3559F6EF9F1",
"versionEndExcluding": "11.5.1",
"versionStartIncluding": "11.3.0"
},
{
"criteria": "cpe:2.3:o:schneider-electric:tcm_4351b_firmware:11.7.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "73044D19-DBC2-490D-B6F8-714A8C846624"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:schneider-electric:tcm_4351b:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9779F47B-29FB-4F09-854D-FEEFD4692A37"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cybersecurity@se.com"
}