All versions of LS Industrial Systems (LSIS) Co. Ltd LS...
Moderate severity
Unreviewed
Published
Sep 1, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Aug 31, 2022
Published to the GitHub Advisory Database
Sep 1, 2022
Last updated
Jan 27, 2023
All versions of LS Industrial Systems (LSIS) Co. Ltd LS Electric PLCs and XG5000 PLC programming software are affected where passwords are not adequately encrypted during the communication process between the XG5000 software and the affected PLC. This would allow an attacker to identify and decrypt the affected PLC’s password by sniffing the traffic.
References