CVE-2021-37401
28.12.2021, 13:15
An attacker may obtain the user credentials from file servers, backup repositories, or ZLD files saved in SD cards. As a result, the PLC user program may be uploaded, altered, and/or downloaded.Enginsight
Vendor | Product | Version |
---|---|---|
idec | data_file_manager | 𝑥 ≤ 2.12.1 |
idec | windedit | 𝑥 ≤ 1.3.1 |
idec | windldr | 𝑥 ≤ 8.19.1 |
idec | microsmart_plus_fc6b_firmware | 𝑥 ≤ 2.31 |
idec | microsmart_plus_fc6a_firmware | 𝑥 ≤ 1.91 |
idec | microsmart_fc6b_firmware | 𝑥 ≤ 2.31 |
idec | microsmart_fc6a_firmware | 𝑥 ≤ 2.32 |
idec | ft1a_smartaxix_pro_firmware | 𝑥 ≤ 2.31 |
idec | ft1a_smartaxix_lite_firmware | 𝑥 ≤ 2.31 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References