ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes a session token on the network.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Controledge_plc_firmware | Honeywell | r130.2 (including) | r130.2 (including) |
| Controledge_plc_firmware | Honeywell | r140 (including) | r140 (including) |
| Controledge_plc_firmware | Honeywell | r150 (including) | r150 (including) |
| Controledge_plc_firmware | Honeywell | r151 (including) | r151 (including) |