Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability
CVE-2023-6408
8.1HIGH
Key Information:
What is CVE-2023-6408?
A vulnerability exists in Schneider Electric's communication systems which allows for improper enforcement of message integrity during transmission, potentially enabling attackers to execute Man-in-the-Middle attacks. This flaw raises serious concerns for the confidentiality and integrity of data as unauthorized entities might intercept and manipulate communications. If exploited, this vulnerability can result in significant disruptions and a dangerous compromise of sensitive information within the affected systems.
Affected Version(s)
EcoStruxure Control Expert Versions prior to v16.0
EcoStruxure Process Expert Versions prior to v2023
Modicon M340 CPU (part numbers BMXP34*) Versions prior to sv3.60