CVE Published: 04/09/2024 |
CVE Updated: 04/09/2024 |
CVE Year: 2024 Source: jpcert |
Vendor: IDEC Corporation |
Product: FC6A Series MICROSmart All-in-One CPU module Status : PUBLISHED
CVE-2024-41927 Description
Cleartext transmission of sensitive information vulnerability exists in multiple IDEC PLCs. If an attacker sends a specific command to PLC\'s serial communication port, user credentials may be obtained. As a result, the program of the PLC may be obtained, and the PLC may be manipulated.