Insufficiently Protected Credentials in Schneider Electric Modicon PLCs
CVE-2017-6028
What is CVE-2017-6028?
A significant security issue has been identified in Schneider Electric's Modicon PLCs, specifically affecting the Modicon M241 and M251 models across all firmware versions. This vulnerability arises from the inadequate protection of log-in credentials, which are transmitted over the network using Base64 encoding. Such encoding offers minimal security, making these credentials easily susceptible to interception via network sniffing techniques. If exploited, attackers could gain unauthorized access to the web application by utilizing the captured credentials, thereby posing a serious risk to the integrity and security of the control systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Schneider Electric Modicon PLCs Schneider Electric Modicon PLCs
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved