CRITICAL · 9.8

CVE-2017-6028

An Insufficiently Protected Credentials issue was discovered in Schneider Electric Modicon PLCs Modicon M241, all firmware versions, and Modicon M251, all firmware versions. Log-in credentials are sen...

Vulnerability Description

An Insufficiently Protected Credentials issue was discovered in Schneider Electric Modicon PLCs Modicon M241, all firmware versions, and Modicon M251, all firmware versions. Log-in credentials are sent over the network with Base64 encoding leaving them susceptible to sniffing. Sniffed credentials could then be used to log into the web application.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Schneider-ElectricModicon M241 Firmware<= 4.0.3.20
Schneider-ElectricModicon M241-
Schneider-ElectricModicon M251 Firmware<= 4.0.3.20
Schneider-ElectricModicon M251-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-6028?

CVE-2017-6028 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An Insufficiently Protected Credentials issue was discovered in Schneider Electric Modicon PLCs Modicon M241, all firmware versions, and Modicon M251, all firmware versions. Log-in credentials are sen...

How severe is CVE-2017-6028?

CVE-2017-6028 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2017-6028?

Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Modicon M241 Firmware, Schneider-Electric Modicon M241, Schneider-Electric Modicon M251 Firmware, Schneider-Electric Modicon M251.