Idec manufactures industrial automation and control products—including programmable logic controllers, firmware, and data management tools such as WindLDR and MicroSmart series devices—that operate in manufacturing and infrastructure environments where credential and configuration exposure carries high operational risk. Vulnerabilities affecting the vendor skew strongly toward critical severity and recur through weakness classes centered on credential protection, cleartext storage, and cleartext transmission, reflecting shortfalls in secrets handling that are particularly consequential in devices with persistent, mission-critical roles. Defenders should prioritize inventory and network segmentation of affected Idec control devices and audit credential storage practices; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Idec over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-37400CRITICAL An attacker may obtain the user credentials from the communication between the PLC and the software. As a result, the PLC user program may be uploaded, altered, and/or downloaded. | Dec 28, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-37401CRITICAL An attacker may obtain the user credentials from file servers, backup repositories, or ZLD files saved in SD cards. As a result, the PLC user program may be uploaded, altered, and/ | Dec 28, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-20826HIGH Unprotected transport of credentials vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSmart Plus CPU module v1.91 and ea | Dec 24, 2021 | 7.6 | 25 | NO | NO |
CVE-2021-20827HIGH Plaintext storage of a password vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSmart Plus CPU module v1.91 and earlier | Dec 24, 2021 | 7.5 | 24 | NO | NO |
CVE-2024-41716HIGH Cleartext storage of sensitive information vulnerability exists in WindLDR and WindO/I-NV4. If this vulnerability is exploited, an attacker who obtained the product's project file | Sep 4, 2024 | 8.1 | 23 | NO | NO |
CVE-2024-41927MEDIUM Cleartext transmission of sensitive information vulnerability exists in multiple IDEC PLCs. If an attacker sends a specific command to PLC's serial communication port, user credent | Sep 4, 2024 | 4.6 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Idec.
Media articles that mention a CVE ID that affects a product developed by Idec — matched by CVE ID, not by vendor name.