CVE-2017-6028
CRITICALSchneider-electric Modicon M241 Firmware < 4.0.3.20 - Insufficiently Protected Credentials
Title source: ruleDescription
An Insufficiently Protected Credentials issue was discovered in Schneider Electric Modicon PLCs Modicon M241, all firmware versions, and Modicon M251, all firmware versions. Log-in credentials are sent over the network with Base64 encoding leaving them susceptible to sniffing. Sniffed credentials could then be used to log into the web application.
Scores
CVSS v3
9.8
EPSS
0.0032
EPSS Percentile
54.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-522
Status
draft
Affected Products (2)
schneider-electric/modicon_m241_firmware
< 4.0.3.20
schneider-electric/modicon_m251_firmware
< 4.0.3.20
Timeline
Published
Jun 30, 2017
Tracked Since
Feb 18, 2026