Description
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when a brute force attack is done over Modbus.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-20696 | A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when a brute force attack is done over Modbus. |
References
| Link | Providers |
|---|---|
| https://www.se.com/ww/en/download/document/SEVD-2020-315-07 |
|
History
No history.
Status: PUBLISHED
Assigner: schneider
Published:
Updated: 2024-08-04T16:33:58.114Z
Reserved: 2020-11-05T00:00:00.000Z
Link: CVE-2020-28212
No data.
Status : Modified
Published: 2020-11-19T22:15:13.490
Modified: 2024-11-21T05:22:29.043
Link: CVE-2020-28212
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD