CVE-2021-37401 Information

Description

An attacker may obtain the user credentials from file servers backup repositories or ZLD files saved in SD cards. As a result the PLC user program may be uploaded altered and/or downloaded.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Reference

https://us.idec.com/idec-us/en/USD/Software-Downloads-Automation-Organizer https://www.idec.com/home/lp/pdf/2021-12-24-PLC.pdf https://us.idec.com/idec-us/en/USD/Programmable-Logic-Controller/Micro-PLC/FC6A-MicroSmart/c/MicroSmart_FC6A https://jvn.jp/en/vu/JVNVU92279973/

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

9.8

Share on: