Schneider Electric Modicon Quantum PLC does not perform authentication between the Unity software and PLC, which allows remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-12-020-03.pdf | broken link |
http://www.securityfocus.com/bid/51605 | vdb entry third party advisory |
http://secunia.com/advisories/47723 | third party advisory not applicable |
https://exchange.xforce.ibmcloud.com/vulnerabilities/72586 | vdb entry third party advisory |
https://us-cert.cisa.gov/ics/alerts/ICS-ALERT-12-020-03 | third party advisory us government resource |