Discover the Insufficiently Protected Credentials issue in Schneider Electric Modicon PLCs Modicon M241 and M251. Learn about the impact, affected systems, and mitigation steps.
A security vulnerability has been found in Schneider Electric Modicon PLCs Modicon M241 and Modicon M251, allowing unauthorized access to the web application.
Understanding CVE-2017-6028
This CVE identifies an Insufficiently Protected Credentials issue in Schneider Electric Modicon PLCs.
What is CVE-2017-6028?
The vulnerability arises from the way log-in credentials are transmitted over the network using Base64 encoding, making them vulnerable to interception by malicious actors.
The Impact of CVE-2017-6028
If exploited, attackers can intercept credentials and gain unauthorized access to the web application, potentially leading to further compromise of the system.
Technical Details of CVE-2017-6028
This section provides more technical insights into the vulnerability.
Vulnerability Description
The issue affects all firmware versions of Schneider Electric Modicon PLCs Modicon M241 and Modicon M251, where log-in credentials are inadequately protected during transmission.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Protecting systems from CVE-2017-6028 is crucial to prevent unauthorized access and potential system compromise.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates