A CWE-73: External Control of File Name or Path vulnerability exists that could cause loading of unauthorized firmware images when user-controlled data is written to the file path. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)
The product allows user input to control or influence paths or file names that are used in filesystem operations.
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.