vendor:
PLC
by:
Deneut Tijl
9.1
CVSS
CRITICAL
Session Calculation
200
CWE
Product Name: PLC
Affected Version From: Schneider Electric PLC 4.0.2.11 & Boot v0.0.2.11
Affected Version To: Schneider Electric PLC 4.0.2.11 & Boot v0.0.2.11
Patch Exists: YES
Related CWE: CVE-2017-6026
CPE: a:schneider_electric:plc:4.0.2.11
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
Schneider Session Calculation – CVE-2017-6026
This script will calculate the website session cookie, which is static after every reboot. After retrieving the cookie, various website actions are possible (including a DoS).
Mitigation:
Ensure that the default passwords are changed and that the system is updated with the latest security patches.