QID 591028
Date Published: 2022-09-05
QID 591028: Schneider Electric Modicon M241/M251 Vulnerability (SEVD-2017-075-02)
AFFECTED PRODUCTS
Schneider Electric Modicon M241
Schneider Electric Modicon M251
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
The session numbering is lacking randomization and is shared between several users. This could allow for hacking of currently opened sessions by using a specially crafted cookie.
Solution
Customers are advised to refer to CERT MITIGATIONS section SEVD-2017-075-02 for affected packages and patching details.
Vendor References
- SEVD-2017-075-02 -
www.se.com/my/en/download/document/SEVD-2017-075-02/
CVEs related to QID 591028
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SEVD-2017-075-02 |
|