logo

Hardening Schneider M221 PLCs Against Attack

ID: bd5d0ce2-37d9-5d2c-a739-51db502d5c29

STIX ID: report--bd5d0ce2-37d9-5d2c-a739-51db502d5c29

Feed Name: Claroty Team82

Threat Score
70/100

Date Published: 2023-09-20

Date Updated: 2026-04-17

Author: Yehuda Anikster

...
...

Team82/Claroty disclosed four vulnerabilities (CVE-2020-7565–7568) in Schneider Electric's Modicon M221 PLCs and EcoStruxure Machine Expert Basic that use weak 4-byte XOR encryption and undersized Diffie-Hellman secrets, allowing an attacker with OT network access to deduce secrets, recover password hashes (enabling Pass‑the‑Hash), read protected memory, bypass authentication, and upload or modify PLC code; Schneider provided mitigations including network segmentation, blocking TCP/502, disabling unused protocols, and vendor patches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.