Fortinet Discovers Schneider Electric Modicon Insecure Credential Transmission Vulnerability
Summary
Fortinet's FortiGuard Labs has discovered a cleartext transmission of sensitive information vulnerability in Schneider Electric Modicon products.
The Modicon PLC (Programmable Logic Controllers) control and monitor industrial operations in a sustainable, flexible, efficient and protected way.
The vulnerability exists because the login credentials are sent over the network in cleartext Base64 encoding. Attackers who can observe cleartext user credentials may be able to log in to the web application and perform unauthorized data monitoring or unauthorized operations.
Solutions
FortiGuard Labs released the following FortiGate IPS signature which covers this specific vulnerability:Schneider.Electric.Modicon.Insecure.Credential.Transmission
Released Sep 07, 2020
Users should apply the solution provided by Schneider Electric.
Timeline
Fortinet reported the vulnerability to Schenider Electric on July 29, 2020.
Schneider Electric confirmed the vulnerability on August 4, 2020.
Schneider Electric patched the vulnerability on October 13, 2020.