QID 590487
Date Published: 2021-09-07
QID 590487: Schneider Electric Modicon PLCs Multiple Vulnerabilities (ICSA-17-089-02)
AFFECTED PRODUCTS
The following versions of the Modicon M221, M241, and M251 programmable logic controllers (PLCs) are affected by a predictable value range from previous values vulnerability:
Modicon M221, firmware versions prior to Version 1.5.0.0,
Modicon M241, firmware versions prior to Version 4.0.5.11, and
Modicon M251, firmware versions prior to Version 4.0.5.11.
The following versions of the Modicon M241 and M251 PLCs are affected by a use of insufficiently random values vulnerability:
Modicon M241, firmware versions prior to Version 4.0.5.11, and
Modicon M251, firmware versions prior to Version 4.0.5.11.
The following versions of the Modicon M241 and M251 PLCs are affected by an insufficiently protected credentials vulnerability:
Modicon M241, all firmware versions, and
Modicon M251, all firmware versions.
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
Successful exploitation of these vulnerabilities may allow a remote attacker to spoof or disrupt Transmission Control Protocol (TCP) connections, sniff sensitive account information, and gain unauthorized access to a current web session.
Customers are advised to refer to CERT MITIGATIONS section ICSA-17-089-02 for affected packages and patching details.
- ICSA-17-089-02 -
www.us-cert.gov/ics/advisories/ICSA-17-089-02
CVEs related to QID 590487
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-17-089-02 |
|