SB2024083016 - Multiple vulnerabilities in IDEC Programmable Logic Controllers



SB2024083016 - Multiple vulnerabilities in IDEC Programmable Logic Controllers

Published: August 30, 2024

Security Bulletin ID SB2024083016
Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Generation of Predictable Numbers or Identifiers (CVE-ID: CVE-2024-28957)

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to generation of predictable numbers or identifiers. A remote attacker can predict some packet header IDs of the device and interfere communications.


2) Cleartext transmission of sensitive information (CVE-ID: CVE-2024-41927)

The vulnerability allows a local attacker to gain access to sensitive information.

The vulnerability exists due to software uses insecure communication channel to transmit sensitive information. An attacker with physical access can gain access to sensitive data.


Remediation

Install update from vendor's website.