Hardening Schneider M221 PLCs Against Attack
ID: bd5d0ce2-37d9-5d2c-a739-51db502d5c29
STIX ID: report--bd5d0ce2-37d9-5d2c-a739-51db502d5c29
Feed Name: Claroty Team82
Team82/Claroty disclosed four vulnerabilities (CVE-2020-7565–7568) in Schneider Electric's Modicon M221 PLCs and EcoStruxure Machine Expert Basic that use weak 4-byte XOR encryption and undersized Diffie-Hellman secrets, allowing an attacker with OT network access to deduce secrets, recover password hashes (enabling Pass‑the‑Hash), read protected memory, bypass authentication, and upload or modify PLC code; Schneider provided mitigations including network segmentation, blocking TCP/502, disabling unused protocols, and vendor patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
