Vulnerability Description
An attacker may obtain the user credentials from the communication between the PLC and the software. As a result, the PLC user program may be uploaded, altered, and/or downloaded.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Idec | Data File Manager | <= 2.12.1 |
| Idec | Windedit | <= 1.3.1 |
| Idec | Windldr | <= 8.19.1 |
| Idec | Microsmart Plus Fc6B Firmware | <= 2.31 |
| Idec | Microsmart Plus Fc6B | - |
| Idec | Microsmart Plus Fc6A Firmware | <= 1.91 |
| Idec | Microsmart Plus Fc6A | - |
| Idec | Microsmart Fc6B Firmware | <= 2.31 |
| Idec | Microsmart Fc6B | - |
| Idec | Microsmart Fc6A Firmware | <= 2.32 |
| Idec | Microsmart Fc6A | - |
| Idec | Ft1A Smartaxix Pro Firmware | <= 2.31 |
| Idec | Ft1A Smartaxix Pro | - |
| Idec | Ft1A Smartaxix Lite Firmware | <= 2.31 |
| Idec | Ft1A Smartaxix Lite | - |
Related Weaknesses (CWE)
References
- https://jvn.jp/en/vu/JVNVU92279973/Third Party Advisory
- https://us.idec.com/idec-us/en/USD/Programmable-Logic-Controller/Micro-PLC/FC6A-Vendor Advisory
- https://us.idec.com/idec-us/en/USD/Software-Downloads-Automation-OrganizerVendor Advisory
- https://www.idec.com/home/lp/pdf/2021-12-24-PLC.pdfVendor Advisory
- https://jvn.jp/en/vu/JVNVU92279973/Third Party Advisory
- https://us.idec.com/idec-us/en/USD/Programmable-Logic-Controller/Micro-PLC/FC6A-Vendor Advisory
- https://us.idec.com/idec-us/en/USD/Software-Downloads-Automation-OrganizerVendor Advisory
- https://www.idec.com/home/lp/pdf/2021-12-24-PLC.pdfVendor Advisory
FAQ
What is CVE-2021-37400?
CVE-2021-37400 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An attacker may obtain the user credentials from the communication between the PLC and the software. As a result, the PLC user program may be uploaded, altered, and/or downloaded.
How severe is CVE-2021-37400?
CVE-2021-37400 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-37400?
Check the references section above for vendor advisories and patch information. Affected products include: Idec Data File Manager, Idec Windedit, Idec Windldr, Idec Microsmart Plus Fc6B Firmware, Idec Microsmart Plus Fc6B.