Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-6030


A Predictable Value Range from Previous Values issue was discovered in Schneider Electric Modicon PLCs Modicon M221, firmware versions prior to Version 1.5.0.0, Modicon M241, firmware versions prior to Version 4.0.5.11, and Modicon M251, firmware versions prior to Version 4.0.5.11. The affected products generate insufficiently random TCP initial sequence numbers that may allow an attacker to predict the numbers from previous values. This may allow an attacker to spoof or disrupt TCP connections.


Published

2017-06-30T03:29:00.390

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

4.9

Weaknesses
  • Type: Secondary
    CWE-343
  • Type: Primary
    CWE-331

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System schneider-electric modicon_m241_firmware ≤ 4.0.3.20 Yes
Hardware schneider-electric modicon_m241 - No
Operating System schneider-electric modicon_m251_firmware ≤ 4.0.3.20 Yes
Hardware schneider-electric modicon_m251 - No
Operating System schneider-electric modicon_m221_firmware ≤ 1.1.1.5 Yes
Hardware schneider-electric modicon_m221 - No

References