CVE-2021-20827 describes a plaintext password storage vulnerability in several IDEC PLC products, including specific versions of FC6A Series MICROSmart CPU modules, WindLDR, WindEDIT Lite, and Data File Manager. An attacker can obtain PLC Web server user credentials from various sources like file servers or SD card files. This allows unauthorized access to the PLC Web server, potentially leading to PLC hijacking, output manipulation, or system suspension. The vulnerability has a CVSSv3 score of 7.5 (HIGH), indicating a network-based attack with low complexity and high confidentiality impact. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.32CPE matchmatch criteria | cpe:2.3:o:idec:microsmart_fc6a_firmware:*:*:*:*:*:*:*:* | ||
<= 1.91CPE matchmatch criteria | cpe:2.3:o:idec:microsmart_plus_fc6a_firmware:*:*:*:*:*:*:*:* | ||
<= 2.12.1CPE matchmatch criteria | cpe:2.3:a:idec:data_file_manager:*:*:*:*:*:*:*:* | ||
<= 1.3.1CPE matchmatch criteria | cpe:2.3:a:idec:windedit:*:*:*:*:*:*:*:* | ||
<= 8.19.1CPE matchmatch criteria | cpe:2.3:a:idec:windldr:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.