CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Cleartext storage of sensitive information vulnerability exists in WindLDR and WindO/I-NV4. If this vulnerability is exploited, an attacker who obtained the product's project file may obtain user credentials of the PLC o...Show more |
1Idec 9Data File Manager Ft1a Smartaxix Lite FirmwareFt1a Smartaxix Pro Firmware+6 moreNov 21, 2024 Dec 28, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An attacker may obtain the user credentials from file servers, backup repositories, or ZLD files saved in SD cards. As a result, the PLC user program may be uploaded, altered, and/or downloaded. |
1Idec 9Data File Manager Ft1a Smartaxix Lite FirmwareFt1a Smartaxix Pro Firmware+6 moreNov 21, 2024 Dec 28, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An attacker may obtain the user credentials from the communication between the PLC and the software. As a result, the PLC user program may be uploaded, altered, and/or downloaded. |
1Idec 5Data File Manager Microsmart Fc6a FirmwareMicrosmart Plus Fc6a Firmware+2 moreNov 21, 2024 Dec 24, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Plaintext storage of a password vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSmart Plus CPU module v1.91 and earlier, WindLDR v8.19.1 and earlier, WindEDIT...Show more |
1Idec 5Data File Manager Microsmart Fc6a FirmwareMicrosmart Plus Fc6a Firmware+2 moreNov 21, 2024 Dec 24, 2021 N/A· v4 7.6 HIGH· v3 3.3 LOW· v2 Unprotected transport of credentials vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSmart Plus CPU module v1.91 and earlier, WindLDR v8.19.1 and earlier, Wind...Show more |