An Insufficiently Protected Credentials issue was discovered in Schneider Electric Modicon PLCs Modicon M241, all firmware versions, and Modicon M251, all firmware versions. Log-in credentials are sent over the network with Base64 encoding leaving them susceptible to sniffing. Sniffed credentials could then be used to log into the web application.
2017-06-30T03:29:00.360
2025-04-20T01:37:25.860
Deferred
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | schneider-electric | modicon_m241_firmware | ≤ 4.0.3.20 | Yes |
Hardware | schneider-electric | modicon_m241 | - | No |
Operating System | schneider-electric | modicon_m251_firmware | ≤ 4.0.3.20 | Yes |
Hardware | schneider-electric | modicon_m251 | - | No |