LS ELECTRIC PLC and XG5000 (Update A)
LS ELECTRIC PLC and XG5000 software contain a weak cryptography vulnerability (CWE-326) that allows attackers to decrypt stored credentials. Successful exploitation grants full access to the affected programmable logic controller, enabling modification of control logic, process parameters, and operational commands. Affected products include XGK-CPUU/H/A/S/E firmware versions below 3.50, XGI-CPUU/UD/H/S/E below 3.20, XGR-CPUH below 1.80, XGB-XBMS below 3.00, XGB-XBCH below 1.90, XGB-XECH below 1.30, and XG5000 below version 4.0.
- Network access to the PLC or XG5000 device or engineering workstation on the control network
- Ability to extract or intercept encrypted credential material from the device or workstation
Patching may require device reboot — plan for process interruption
/api/v1/advisories/71ccfca2-1622-4d23-aaa4-5ef5186417e0Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.