Description

An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to systems and services. The limited password complexity and no password input limiters makes brute force password enumeration possible.

INFO

Published Date :

2026-04-17T15:14:06.346Z

Last Modified :

2026-04-20T14:58:32.621Z

Source :

icscert
AFFECTED PRODUCTS

The following products are affected by CVE-2026-6284 vulnerability.

Vendors Products
Hornerautomation
  • Cscape
  • Xl4 Plc
  • Xl7 Plc

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact