PatchSiren

IDEC Corporation CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM IDEC Corporation CVE published 2024-09-19

CVE-2024-41927

A cleartext transmission vulnerability in IDEC Corporation industrial control system (ICS) products allows attackers with physical access to obtain user authentication information. The vulnerability affects multiple CPU module series used in programmable logic controllers (PLCs) and related industrial automation equipment. CISA published the initial advisory on September 19, 2024, with subsequent updates [truncated]

MEDIUM IDEC Corporation CVE published 2024-09-19

CVE-2024-41716

IDEC Corporation WindLDR and WindO/I-NV4 contain a cleartext storage vulnerability that could allow an attacker to obtain user authentication information. The vulnerability affects WindLDR versions 9.1.0 and earlier, and WindO/I-NV4 versions 3.0.1 and earlier. CISA published advisory ICSA-24-263-03 on September 19, 2024, identifying this as a cleartext vulnerability with network attack vector, high attack [truncated]