CVE-2026-6284 affects programmable logic controllers (PLCs) and involves weak password security mechanisms that enable attackers to conduct brute force attacks against protected systems and services. The vulnerability stems from insufficient password complexity requirements and the absence of login attempt rate limiting controls. The vulnerability presents a critical severity risk with a CVSS score of 9.1, requiring only network access and no authentication or user interaction for exploitation. The attack successfully compromises confidentiality and integrity of affected systems, though availability is not directly impacted. There is currently no evidence of active exploitation in the wild, and the vulnerability does not appear on the CISA Known Exploited Vulnerabilities catalog. Community attention remains minimal based on available threat intelligence, with EPSS metrics indicating lower probability of exploitation compared to broader CVE populations. However, the absence of exploitation activity should not diminish concern given the critical severity rating and the straightforward nature of brute force attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Horner Automation | Cscape | 10.0CNA affecteddefault unaffected | |
| Horner Automation | XL4 PLC | 16.32.0CNA affecteddefault unaffected | |
| Horner Automation | XL7 PLC | 15.60CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.