Schneider Electric Addresses M221 PLC Vulnerabilities Found by Team82
ID: 30292bce-6107-5582-868f-06aed39dbc40
STIX ID: report--30292bce-6107-5582-868f-06aed39dbc40
Feed Name: Claroty Team82
Schneider Electric disclosed multiple cryptographic and authentication vulnerabilities in Modicon M221 PLCs and EcoStruxure Machine Expert-Basic (including CVE-2020-28214 and related CVEs) that enable attacks such as rainbow-table precomputed hash cracking, weak XOR read/write encryption, small Diffie-Hellman secrets, and exposure of readable memory regions; mitigations and configuration recommendations are provided, and exploitation generally requires an attacker to already have access to the device or network.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
