QID 590488
Date Published: 2021-09-07
QID 590488: Schneider Electric Modicon PLCs Insufficiently Protected Credentials Vulnerability (ICSA-17-089-02)
AFFECTED PRODUCTS
Modicon M241 Logic Controller, firmware version prior to 5.0.8.4
Modicon M251 Logic Controller, firmware version prior to 5.0.8.4
Modicon Quantum Co-processors ref. 140CPU6*
Modicon Premium Co-processors ref. TSXP* and TSXH*
Modicon Quantum Ethernet communication modules ref.140NOE* and 140NOC*
Modicon Premium Ethernet communication modules ref. TSXETY*
Modicon M340 CPU ref. BMXP34*
Modicon M340 Ethernet communication Modules ref. BMXNOC*, BMXNOE*, BMXNOR*
Modicon Momentum Ethernet MDI
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
Successful exploitation of these vulnerabilities may allow a remote attacker to spoof or disrupt Transmission Control Protocol (TCP) connections, sniff sensitive account information, and gain unauthorized access to a current web session.
Customers are advised to refer to CERT MITIGATIONS section SEVD-2017-075-03,SEVD-2017-075-03 for affected packages and patching details.
- ICSA-17-089-02 -
www.us-cert.gov/ics/advisories/ICSA-17-089-02 - SEVD-2017-075-03 -
www.se.com/ww/en/download/document/SEVD-2017-075-03/
CVEs related to QID 590488
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-17-089-02 |
|