CVE-2021-37401

EUVD-2021-23970
An attacker may obtain the user credentials from file servers, backup repositories, or ZLD files saved in SD cards. As a result, the PLC user program may be uploaded, altered, and/or downloaded.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
Affected Products (NVD)
VendorProductVersion
idecdata_file_manager
𝑥
≤ 2.12.1
idecwindedit
𝑥
≤ 1.3.1
idecwindldr
𝑥
≤ 8.19.1
idecmicrosmart_plus_fc6b_firmware
𝑥
≤ 2.31
idecmicrosmart_plus_fc6a_firmware
𝑥
≤ 1.91
idecmicrosmart_fc6b_firmware
𝑥
≤ 2.31
idecmicrosmart_fc6a_firmware
𝑥
≤ 2.32
idecft1a_smartaxix_pro_firmware
𝑥
≤ 2.31
idecft1a_smartaxix_lite_firmware
𝑥
≤ 2.31
𝑥
= Vulnerable software versions