logo

Schneider Electric Addresses M221 PLC Vulnerabilities Found by Team82

ID: 30292bce-6107-5582-868f-06aed39dbc40

STIX ID: report--30292bce-6107-5582-868f-06aed39dbc40

Feed Name: Claroty Team82

Threat Score
65/100

Date Published: 2023-09-20

Date Updated: 2026-04-17

Author: Yehuda Anikster

...
...

Schneider Electric disclosed multiple cryptographic and authentication vulnerabilities in Modicon M221 PLCs and EcoStruxure Machine Expert-Basic (including CVE-2020-28214 and related CVEs) that enable attacks such as rainbow-table precomputed hash cracking, weak XOR read/write encryption, small Diffie-Hellman secrets, and exposure of readable memory regions; mitigations and configuration recommendations are provided, and exploitation generally requires an attacker to already have access to the device or network.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.