A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists which could allow the attacker to execute malicious code on the Modicon M218, M241, M251, and M258 controllers.
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ecostruxure_machine_expert | Schneider-electric | * | * |
Somachine | Schneider-electric | * | * |
Somachine_motion | Schneider-electric | * | * |