PT-2017-4198 · Schneider Electric · Modicon M251+1

David Formby

+1

·

Publicado

2017-03-30

·

Atualizado

2022-02-03

·

CVE-2017-6028

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Modicon M241 versions all firmware versions Modicon M251 versions all firmware versions
Description An issue was discovered where log-in credentials are sent over the network with Base64 encoding, leaving them susceptible to sniffing. Sniffed credentials could then be used to log into the web application. This issue is related to insufficient protection of credentials, which could allow a remote attacker to intercept credentials and gain access to the web application.
Recommendations For Modicon M241, consider implementing additional security measures to protect log-in credentials, such as encryption or secure transmission protocols, until a patch is available. For Modicon M251, restrict access to the web application and consider using alternative authentication methods to minimize the risk of exploitation. As a temporary workaround, consider disabling remote access to the web application for both Modicon M241 and Modicon M251 until the issue is resolved.

Correção

Insufficiently Protected Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-04700
CVE-2017-6028

Produtos afetados

Modicon M241
Modicon M251