Description
A Predictable Value Range from Previous Values issue was discovered in Schneider Electric Modicon PLCs Modicon M221, firmware versions prior to Version 1.5.0.0, Modicon M241, firmware versions prior to Version 4.0.5.11, and Modicon M251, firmware versions prior to Version 4.0.5.11. The affected products generate insufficiently random TCP initial sequence numbers that may allow an attacker to predict the numbers from previous values. This may allow an attacker to spoof or disrupt TCP connections.
Published: 2017-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2017-15098 A Predictable Value Range from Previous Values issue was discovered in Schneider Electric Modicon PLCs Modicon M221, firmware versions prior to Version 1.5.0.0, Modicon M241, firmware versions prior to Version 4.0.5.11, and Modicon M251, firmware versions prior to Version 4.0.5.11. The affected products generate insufficiently random TCP initial sequence numbers that may allow an attacker to predict the numbers from previous values. This may allow an attacker to spoof or disrupt TCP connections.
History

No history.

Subscriptions

Schneider-electric Modicon M221 Modicon M221 Firmware Modicon M241 Modicon M241 Firmware Modicon M251 Modicon M251 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-05T15:18:49.582Z

Reserved: 2017-02-16T00:00:00.000Z

Link: CVE-2017-6030

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-06-30T03:29:00.390

Modified: 2025-04-20T01:37:25.860

Link: CVE-2017-6030

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses