First published: Tue Oct 17 2023(Updated: )
Eaton easyE4 PLC offers a device password protection functionality to facilitate a secure connection and prevent unauthorized access. It was observed that the device password was stored with a weak encoding algorithm in the easyE4 program file when exported to SD card (*.PRG file ending).
Credit: CybersecurityCOE@eaton.com CybersecurityCOE@eaton.com
Affected Software | Affected Version | How to fix |
---|---|---|
Eaton Easy-box-e4-ac1 Firmware | <2.02 | |
Eaton Easy-box-e4-ac1 | ||
Eaton Easy-box-e4-dc1 Firmware | <2.02 | |
Eaton Easy-box-e4-dc1 | ||
Eaton Easy-box-e4-uc1 Firmware | <2.02 | |
Eaton Easy-box-e4-uc1 | ||
Eaton Easy-e4-ac-12rc1p Firmware | <2.02 | |
Eaton Easy-e4-ac-12rc1p | ||
Eaton Easy-e4-ac-12rcx1p Firmware | <2.02 | |
Eaton Easy-e4-ac-12rcx1p | ||
Eaton Easy-e4-ac-16re1p Firmware | <2.02 | |
Eaton Easy-e4-ac-16re1p | ||
Eaton Easy E4-ac-8re1p Firmware | <2.02 | |
Eaton Easy E4-ac-8re1p | ||
Eaton Easy-e4-dc-12tc1p Firmware | <2.02 | |
Eaton Easy-e4-dc-12tc1p | ||
Eaton Easy-e4-dc-12tcx1p Firmware | <2.02 | |
Eaton Easy-e4-dc-12tcx1p | ||
Eaton Easy-e4-dc-16te1p Firmware | <2.02 | |
Eaton Easy-e4-dc-16te1p | ||
Eaton Easy-e4-dc-4pe1p Firmware | <2.02 | |
Eaton Easy-e4-dc-4pe1p | ||
Eaton Easy-e4-dc-6ae1p Firmware | <2.02 | |
Eaton Easy-e4-dc-6ae1p | ||
Eaton Easy-e4-dc-8te1p Firmware | <2.02 | |
Eaton Easy-e4-dc-8te1p | ||
Eaton Easy-e4-uc-12rc1p Firmware | <2.02 | |
Eaton Easy-e4-uc-12rc1p | ||
Eaton Easy-e4-uc-12rcx1p Firmware | <2.02 | |
Eaton Easy-e4-uc-12rcx1p | ||
Eaton Easy-e4-uc-16re1 Firmware | <2.02 | |
Eaton Easy-e4-uc-16re1 | ||
Eaton Easy-e4-uc-16re1p Firmware | <2.02 | |
Eaton Easy-e4-uc-16re1p | ||
Eaton Easy-e4-uc-8re1p Firmware | <2.02 | |
Eaton Easy-e4-uc-8re1p | ||
Eaton Xv-102-a035tqrb-1e4 Firmware | <2.02 | |
Eaton Xv-102-a035tqrb-1e4 | ||
Eaton Xv-102-a3-57tvrb-1e4 Firmware | <2.02 | |
Eaton Xv-102-a3-57tvrb-1e4 | ||
Eaton Xv100-box-e4-dc1 Firmware | <2.02 | |
Eaton Xv100-box-e4-dc1 | ||
Eaton Xv100-box-e4-uc1 Firmware | <2.02 | |
Eaton Xv100-box-e4-uc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-43776.
The severity level of CVE-2023-43776 is medium with a score of 6.8.
CVE-2023-43776 impacts Eaton easyE4 PLC by storing the device password with a weak encoding algorithm in the program file when exported to SD card.
The affected software by CVE-2023-43776 includes Eaton Easy-box-e4-ac1, Eaton Easy-box-e4-dc1, Eaton Easy-box-e4-uc1, Eaton Easy-e4-ac-12rc1p, Eaton Easy-e4-ac-12rcx1p, Eaton Easy-e4-ac-16re1p, Eaton Easy E4-ac-8re1p, Eaton Easy-e4-dc-12tc1p, Eaton Easy-e4-dc-12tcx1p, Eaton Easy-e4-dc-16te1p, Eaton Easy-e4-dc-4pe1p, Eaton Easy-e4-dc-6ae1p, Eaton Easy-e4-dc-8te1p, Eaton Easy-e4-uc-12rc1p, Eaton Easy-e4-uc-12rcx1p, Eaton Easy-e4-uc-16re1, Eaton Easy-e4-uc-16re1p, Eaton Easy-e4-uc-8re1p, Eaton Xv-102-a035tqrb-1e4, Eaton Xv-102-a3-57tvrb-1e4, Eaton Xv100-box-e4-dc1, and Eaton Xv100-box-e4-uc1.
To fix CVE-2023-43776, it is recommended to update the Eaton easyE4 PLC firmware to version 2.03 or higher.