82% (78) 1.8k views 2 pages

Modicon M241 and M251 Authentication Vulnerability Security Notification

AI-enhanced description

This document details an authentication vulnerability in Schneider Electric Modicon M241 and M251 PLCs, where session cookies lack randomization and can be shared between users, potentially allowing session hijacking. The recommended mitigation is to update the firmware to version v4.0.5.11, which improves cookie randomization, prevents session sharing, and adds a logout button.

Uploaded by Mitsubishi@Lab
Download
/ 2
Loading document…