An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to systems and services. The limited password complexity and no password input limiters makes brute force password enumeration possible.
Metrics
Affected Vendors & Products
References
History
Fri, 17 Apr 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hornerautomation
Hornerautomation cscape Hornerautomation xl4 Plc Hornerautomation xl7 Plc |
|
| Vendors & Products |
Hornerautomation
Hornerautomation cscape Hornerautomation xl4 Plc Hornerautomation xl7 Plc |
Fri, 17 Apr 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to systems and services. The limited password complexity and no password input limiters makes brute force password enumeration possible. | |
| Title | Horner Automation Cscape and XL4, XL7 PLC Weak password requirements | |
| Weaknesses | CWE-521 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published: 2026-04-17T15:14:06.346Z
Updated: 2026-04-17T15:14:06.346Z
Reserved: 2026-04-14T15:07:32.676Z
Link: CVE-2026-6284
No data.
Status : Awaiting Analysis
Published: 2026-04-17T16:17:07.620
Modified: 2026-04-17T19:01:56.030
Link: CVE-2026-6284
No data.