ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes a session token on the network.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Controledge_plc_firmware | Honeywell | r130.2 (including) | r130.2 (including) |
Controledge_plc_firmware | Honeywell | r140 (including) | r140 (including) |
Controledge_plc_firmware | Honeywell | r150 (including) | r150 (including) |
Controledge_plc_firmware | Honeywell | r151 (including) | r151 (including) |