ZeroHour

CVE-2021-37400

CVSS 3.1
9.8 critical
EPSS
1%p70
Published
()
Modified
Description

An attacker may obtain the user credentials from the communication between the PLC and the software. As a result, the PLC user program may be uploaded, altered, and/or downloaded.

Vendors
idec
Products
data file manager, windedit, windldr, microsmart plus fc6b firmware, microsmart plus fc6a firmware, microsmart fc6b firmware, microsmart fc6a firmware, ft1a smartaxix pro firmware, ft1a smartaxix lite firmware
Weakness
CWE-522
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.