A CWE-326: Inadequate Encryption Strength vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to break the encryption key when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller.
CVE Status: Modified
Attribute | Value |
---|---|
Attack Complexity | LOW |
Attack Vector | ADJACENT_NETWORK |
Availability Impact | NONE |
Base Score | 7.3 |
Base Severity | HIGH |
Confidentiality Impact | HIGH |
Integrity Impact | HIGH |
Privileges Required | NONE |
Scope | UNCHANGED |
User Interaction | REQUIRED |
Vector String | CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
Exploitability Score | 2.1 |
Impact Score | 5.2 |
Source | [email protected] |
Type | Primary |