CVE-2017-6026 EXPLOIT
9.1
CRITICAL · CVSS 3.1 · EPSS 31.8% (pctl 98)
Patch early
A public exploit exists.
Description
A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware versions prior to Version 4.0.5.11, and Modicon M251, firmware versions prior to Version 4.0.5.11. The session numbers generated by the web application are lacking randomization and are shared between several users. This may allow a current session to be compromised.
Scoring
| CVSS | 9.1 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| EPSS | 31.82% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-330 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-06-30 |
| Last modified | 2026-06-17 |
Affected (4)
| Vendor | Product |
|---|---|
| schneider-electric | modicon m241 |
| schneider-electric | modicon m241 firmware |
| schneider-electric | modicon m251 |
| schneider-electric | modicon m251 firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Schneider Electric PLC - Session Calculation Authentication Bypass | 2018-11-30 |
References
→ the Explorer · watch your stack · NVD