An Authentication Bypass by Capture-Replay issue was discovered in Schneider Electric Modicon Modbus Protocol. Sensitive information is transmitted in cleartext in the Modicon Modbus protocol, which may allow an attacker to replay the following commands: run, stop, upload, and download.
References
Link | Resource |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-17-101-01 | US Government Resource Third Party Advisory |
http://www.securityfocus.com/bid/97562 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2017-06-29 20:29
Updated : 2019-10-09 16:28
NVD link : CVE-2017-6034
Mitre link : CVE-2017-6034
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
schneider-electric
- modbus_firmware
- modbus