ZeroHour

CVE-2024-41927

CVSS 3.1
4.6 medium
EPSS
<1%p5
Published
()
Modified
Description

Cleartext transmission of sensitive information vulnerability exists in multiple IDEC PLCs. If an attacker sends a specific command to PLC's serial communication port, user credentials may be obtained. As a result, the program of the PLC may be obtained, and the PLC may be manipulated.

Vendors
idec
Products
kit-fc6a-24-kc firmware, kit-fc6a-24-pc firmware, kit-fc6a-24-ra firmware, kit-fc6a-24-ra-hg1g firmware, kit-fc6a-24-ra-hg2g-5tn firmware, kit-fc6a-24-ra-hg2g-5tt firmware, kit-fc6a-24-rc-hg1g firmware, kit-fc6a-24-rc firmware, kit-fc6a-24-rc-hg2g-5tn firmware, kit-fc6a-24-rc-hg2g-5tt firmware, kit-fc6a-c24r-hg2g-vhp firmware, kit-fc6a-c24r-hg3g-v8hp firmware
Weakness
CWE-319
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.