CVE-2017-6028

CVE-2017-6028

Vendor N/A
Product Schneider Electric Modicon PLCs
Weakness CWE-522 · Insufficiently protected credentials
Published June 30, 2017
Last update August 5, 2024

CVSS base score

What the vulnerability does

01Description

An Insufficiently Protected Credentials issue was discovered in Schneider Electric Modicon PLCs Modicon M241, all firmware versions, and Modicon M251, all firmware versions. Log-in credentials are sent over the network with Base64 encoding leaving them susceptible to sniffing. Sniffed credentials could then be used to log into the web application.

Key dates

02Disclosure timeline

June 30, 2017 CVE published
August 5, 2024 Record updated