#VU59296 Unprotected Transport of Credentials in IDEC Corporation products - CVE-2021-20826

 

#VU59296 Unprotected Transport of Credentials in IDEC Corporation products - CVE-2021-20826

Published: January 7, 2022


Vulnerability identifier: #VU59296
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2021-20826
CWE-ID: CWE-523
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
FC6A MICROSmart All-in-One CPU Module
FC6B MICROSmart All-in-One CPU Module
FC6A MICROSmart Plus CPU Module
FC6B MICROSmart Plus CPU Module
FT1A Controller SmartAXIS Pro/Lite
WindLDR
WindEDIT Lite
Data File Manager
WindEDIT
Software vendor:
IDEC Corporation

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to password leakage. A remote attacker on the local network can obtain the PLC web server user credentials from the communication between the PLC and the software.


Remediation

Install updates from vendor's website.

External links