QID 590486
Date Published: 2021-08-10
QID 590486: Schneider Electric Modicon M221 PLCs Multiple Vulnerabilities(ICSA-17-103-02A)
AFFECTED PRODUCTS
Schneider Electric reports that these vulnerabilities affect the following PLCs and tools for configuring and developing automation machinery:
All Modicon M221 PLCs with firmware version up to v1.5.0.1 .
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
One vulnerability may allow an attacker to extract a protected project file from the controller to obtain sensitive project information. The second vulnerability may allow a user with access to a protected project file to decrypt it in order to obtain sensitive information without authorization.
Solution
Customers are advised to refer to CERT MITIGATIONS section ICSA-17-103-02A for affected packages and patching details.
Vendor References
- ICSA-17-103-02A -
www.us-cert.gov/ics/advisories/ICSA-17-103-02A
CVEs related to QID 590486
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-17-103-02A |
|