An authentication bypass by capture-replay issue was discovered in Schneider Electric Modicon Modbus Protocol. Sensitive information is transmitted in cleartext in the Modicon Modbus protocol, which may allow an attacker to replay the following commands: run, stop, upload, and download.

Project Subscriptions

Vendors Products
Schneider-electric Subscribe
Modbus Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2017-15102 An Authentication Bypass by Capture-Replay issue was discovered in Schneider Electric Modicon Modbus Protocol. Sensitive information is transmitted in cleartext in the Modicon Modbus protocol, which may allow an attacker to replay the following commands: run, stop, upload, and download.
Fixes

Solution

No solution given by the vendor.


Workaround

Schneider Electric has reported that they have introduced compensating controls to limit the exploitability of the identified vulnerabilities in many of the PLCs in the Modicon family; however, Schneider Electric recommends that users apply security measures to improve resiliency. Schneider Electric’s Momentum M1E controllers (all versions of model 171CBU98090 and all versions of model 171CBU98091) do not have built-in compensating controls to limit the exploitability of the identified vulnerabilities and Schneider Electric instructs users to take the following defensive measures: * Protect access to M1E controllers by a firewall blocking all remote/external access to Port 502. Schneider Electric reports that Modicon M340, M580, Premium and Quantum users should take one or more of the following defensive measures: * Enable protection based on an authentication to connect to PLC. This method relies on a feature named Application Password. Once enabled, password-based authentication is required whenever a user connects to change their application program; * Enable protection relying on an input (M340, Premium, Quantum) or a key switch in the front panel (Quantum) to reject remote connection or run/stop commands; and * Enable the “Access Control List protection,” where users are able to configure the restricted IP addresses that are pre-authorized to control the PLC. For additional information, Schneider Electric has released a Cybersecurity Notification, which is available at the following location: https://www.se.com/us/en/download/document/SEVD-2017-065-01/

History

Thu, 04 Jun 2026 21:30:00 +0000

Type Values Removed Values Added
Description An Authentication Bypass by Capture-Replay issue was discovered in Schneider Electric Modicon Modbus Protocol. Sensitive information is transmitted in cleartext in the Modicon Modbus protocol, which may allow an attacker to replay the following commands: run, stop, upload, and download. An authentication bypass by capture-replay issue was discovered in Schneider Electric Modicon Modbus Protocol. Sensitive information is transmitted in cleartext in the Modicon Modbus protocol, which may allow an attacker to replay the following commands: run, stop, upload, and download.
Title Schneider Electric Modicon Modbus Protocol Authentication Bypass by Capture-replay
References

Thu, 28 May 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-06-04T21:07:21.157Z

Reserved: 2017-02-16T00:00:00.000Z

Link: CVE-2017-6034

cve-icon Vulnrichment

Updated: 2024-08-05T15:18:49.398Z

cve-icon NVD

Status : Modified

Published: 2017-06-30T03:29:00.453

Modified: 2026-06-04T22:16:51.503

Link: CVE-2017-6034

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses