Insufficiently Protected Credentials in Schneider Electric Modicon PLCs
CVE-2017-6028

9.8CRITICAL

Key Information:

Vendor
CVE Published:
30 June 2017

Summary

A significant security issue has been identified in Schneider Electric's Modicon PLCs, specifically affecting the Modicon M241 and M251 models across all firmware versions. This vulnerability arises from the inadequate protection of log-in credentials, which are transmitted over the network using Base64 encoding. Such encoding offers minimal security, making these credentials easily susceptible to interception via network sniffing techniques. If exploited, attackers could gain unauthorized access to the web application by utilizing the captured credentials, thereby posing a serious risk to the integrity and security of the control systems.

Affected Version(s)

Schneider Electric Modicon PLCs Schneider Electric Modicon PLCs

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.