Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2017-6026

A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware versions prior to Version 4.0.5.11, and Modicon M251, firmware versions prior to Version 4.0.5.11. The session numbers generated by the web application are lacking randomization and are shared between several users. This may allow a current session to be compromised.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.148
EPSS Ranking 94.1%
CVSS Severity
CVSS v3 Score 9.1
CVSS v2 Score 6.4
Products affected by CVE-2017-6026


Contact Us

Shodan ® - All rights reserved