A CWE-326: Inadequate Encryption Strength vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to break the encryption key when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller.
oryginał ENCVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:NSchneider Electric Modicon M221
HWSchneider-Electricwszystkie wersjeSchneider Electric Modicon M221 Firmware
OSSchneider-Electricwszystkie wersje
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Powiązane podatności
CVE-2020-7489CRITICAL9.8PL ✓ten sam produkt
Podatność Injection w oprogramowaniu Schneider Electric – podstawianie DLL
CVE-2018-7790CRITICAL9.8PL ✓ten sam produkt
Replay attack na uwierzytelnianie w Schneider Electric Modicon M221
CVE-2018-7791CRITICAL9.8PL ✓ten sam produkt
Nieautoryzowane nadpisanie hasła w Schneider Electric Modicon M221
CVE-2020-7566HIGH7.3ten sam produkt
A CWE-334: Small Space of Random Values vulnerability exists in Modicon M221 (all references, all versions) th...
CVE-2018-7821HIGH7.5ten sam produkt
An Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references,...