CVE-2017-6026
Summary
| CVE | CVE-2017-6026 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-06-30 03:29:00 UTC |
| Updated | 2022-02-02 13:05:00 UTC |
| Description | A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware versions prior to Version 4.0.5.11, and Modicon M251, firmware versions prior to Version 4.0.5.11. The session numbers generated by the web application are lacking randomization and are shared between several users. This may allow a current session to be compromised. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Multiple Schneider Electric Modicon Products Weak Cryptography Multiple Security Weaknesses |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Schneider Electric PLC - Session Calculation Authentication Bypass - Hardware webapps Exploit |
EXPLOIT-DB |
www.exploit-db.com |
|
| Schneider Electric Modicon PLCs | ICS-CERT |
MISC |
ics-cert.us-cert.gov |
Third Party Advisory, US Government Resource |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590487 Schneider Electric Modicon PLCs Multiple Vulnerabilities (ICSA-17-089-02)