Vulnerability in Schneider Electric Modicon Modbus Protocol Exposes Systems to Brute-Force Attacks
CVE-2017-6032

5.3MEDIUM

Key Information:

Vendor
CVE Published:
30 June 2017

Summary

A significant design flaw was identified in Schneider Electric's Modicon Modbus Protocol, which exposes systems to the risk of brute-force attacks. This vulnerability arises from inadequate session management, allowing attackers to leverage systematic guessing techniques to potentially gain unauthorized access to sensitive systems. Implementing appropriate security measures and ensuring timely updates are essential to mitigate the risks associated with this vulnerability.

Affected Version(s)

Schneider Electric Modicon Modbus Protocol Schneider Electric Modicon Modbus Protocol

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.