CVE-2021-20826 Details
Description
Unprotected transport of credentials vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSmart Plus CPU module v1.91 and earlier, WindLDR v8.19.1 and earlier, WindEDIT Lite v1.3.1 and earlier, and Data File Manager v2.12.1 and earlier) allows an attacker to obtain the PLC Web server user credentials from the communication between the PLC and the software. As a result, the complete access privileges to the PLC Web server may be obtained, and manipulation of the PLC output and/or suspension of the PLC may be conducted.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jvn.jp/en/vu/JVNVU92279973/index.html | CVE | Third Party Advisory |
| https://www.idec.com/home/lp/pdf/2021-12-24-PLC.pdf | CVE | Vendor Advisory |
| https://jvn.jp/en/vu/JVNVU92279973/index.html | [email protected] | Third Party Advisory |
| https://www.idec.com/home/lp/pdf/2021-12-24-PLC.pdf | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-522 | Insufficiently Protected Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| idec microsmart fc6a firmware | <= 2.32 |
CPE
Remediation
| |
| idec microsmart fc6a | All versions |
CPE
Remediation
| |
| idec microsmart plus fc6a firmware | <= 1.91 |
CPE
Remediation
| |
| idec microsmart plus fc6a | All versions |
CPE
Remediation
| |
| idec data file manager | <= 2.12.1 |
CPE
Remediation
| |
| idec windedit | <= 1.3.1 |
CPE
Remediation
| |
| idec windldr | <= 8.19.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jan 11, 2022 | Initial Analysis | [email protected] |