Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Deneut Tijl

#19013de 53,640
14.1CVSS total
Vulnerabilidades · 2
Média
1
Crítica
1
PT-2018-4996
5.0
2018-04-05
Phoenix Contact · Phoenix Contact Ilc Plcs · CVE-2016-8366
**Name of the Vulnerable Software and Affected Versions** Phoenix Contact ILC PLCs (affected versions not specified) **Description** The issue concerns the storage and transfer of passwords in clear text due to the configuration of the password macro in Webvisit. This macro is intended to protect HMI pages on the PLC against unauthorized access. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2017-16842
9.1
2017-06-30
Schneider Electric · Modicon M251 · CVE-2017-6026
**Name of the Vulnerable Software and Affected Versions** Modicon M241 versions prior to 4.0.5.11 Modicon M251 versions prior to 4.0.5.11 **Description** A Use of Insufficiently Random Values issue was discovered, where the session numbers generated by the web application lack randomization and are shared between several users. This may allow a current session to be compromised. **Recommendations** For Modicon M241 versions prior to 4.0.5.11, update to version 4.0.5.11 or later to resolve the issue. For Modicon M251 versions prior to 4.0.5.11, update to version 4.0.5.11 or later to resolve the issue.