VulnerabilityModified
CVE-2021-37400
An attacker may obtain the user credentials from the communication between the PLC and the software.
CRITICAL 9.8EPSS 1.34%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.34%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An attacker may obtain the user credentials from the communication between the PLC and the software. As a result, the PLC user program may be uploaded, altered, and/or downloaded.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.34% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- idec/data file manager · idec/windedit · idec/windldr · idec/microsmart plus fc6b firmware · idec/microsmart plus fc6a firmware · idec/microsmart fc6b firmware · idec/microsmart fc6a firmware · idec/ft1a smartaxix pro firmware · idec/ft1a smartaxix lite firmware
- Source
- cve@mitre.org
References
- https://jvn.jp/en/vu/JVNVU92279973/Third Party Advisory
- https://us.idec.com/idec-us/en/USD/Programmable-Logic-Controller/Micro-PLC/FC6A-MicroSmart/c/MicroSmart_FC6AVendor Advisory
- https://us.idec.com/idec-us/en/USD/Software-Downloads-Automation-OrganizerVendor Advisory
- https://www.idec.com/home/lp/pdf/2021-12-24-PLC.pdfVendor Advisory
- https://jvn.jp/en/vu/JVNVU92279973/Third Party Advisory
- https://us.idec.com/idec-us/en/USD/Programmable-Logic-Controller/Micro-PLC/FC6A-MicroSmart/c/MicroSmart_FC6AVendor Advisory
- https://us.idec.com/idec-us/en/USD/Software-Downloads-Automation-OrganizerVendor Advisory
- https://www.idec.com/home/lp/pdf/2021-12-24-PLC.pdfVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.