Encryption Key Exposure in Modicon M221 Controllers by Schneider Electric
CVE-2020-7566
7.3HIGH
Summary
A vulnerability in Modicon M221 controllers by Schneider Electric allows attackers to potentially compromise encryption keys when traffic is intercepted between EcoStruxure Machine - Basic software and the controller. This flaw arises from a limited randomness space, which could lead to predictable cryptographic values, exposing sensitive communication channels and potentially enabling unauthorized access to the system.
Affected Version(s)
Modicon M221, all references, all Modicon M221, all references, all versions
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved