Encryption Key Exposure in Modicon M221 Controllers by Schneider Electric
CVE-2020-7566
7.3HIGH
What is CVE-2020-7566?
A vulnerability in Modicon M221 controllers by Schneider Electric allows attackers to potentially compromise encryption keys when traffic is intercepted between EcoStruxure Machine - Basic software and the controller. This flaw arises from a limited randomness space, which could lead to predictable cryptographic values, exposing sensitive communication channels and potentially enabling unauthorized access to the system.
Affected Version(s)
Modicon M221, all references, all Modicon M221, all references, all versions