CVE-2021-37401
moderate-risk
Published 2021-12-28
An attacker may obtain the user credentials from file servers, backup repositories, or ZLD files saved in SD cards. As a result, the PLC user program may be uploaded, altered, and/or downloaded.
Do I need to act?
-
0.70% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.8/10
Critical
NETWORK
/ LOW complexity
Affected Products (9)
Data File Manager
Windedit
Windldr
Microsmart Plus Fc6B Firmware
Microsmart Plus Fc6A Firmware
Microsmart Fc6B Firmware
Microsmart Fc6A Firmware
Ft1A Smartaxix Pro Firmware
Ft1A Smartaxix Lite Firmware
Affected Vendors
References (8)
Third Party Advisory
https://jvn.jp/en/vu/JVNVU92279973/
Vendor Advisory
https://www.idec.com/home/lp/pdf/2021-12-24-PLC.pdf
Third Party Advisory
https://jvn.jp/en/vu/JVNVU92279973/
Vendor Advisory
https://www.idec.com/home/lp/pdf/2021-12-24-PLC.pdf
49
/ 100
moderate-risk
Severity
32/34 · Critical
Exploitability
2/34 · Minimal
Exposure
15/34 · Moderate