HOMEVULNERABILITIESCVE-2021-20826
HIGH

CVE-2021-20826

CWE-522Published: December 24, 2021· Updated: Jun 17, 2026

7.6
CVSS v3.1

Official Description

Unprotected transport of credentials vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSmart Plus CPU module v1.91 and earlier, WindLDR v8.19.1 and earlier, WindEDIT Lite v1.3.1 and earlier, and Data File Manager v2.12.1 and earlier) allows an attacker to obtain the PLC Web server user credentials from the communication between the PLC and the software. As a result, the complete access privileges to the PLC Web server may be obtained, and manipulation of the PLC output and/or suspension of the PLC may be conducted.

NVD Source

Technical Analysis

CVE-2021-20826 requires adjacent network access, limiting remote exploitation but still posing risk in shared or local network environments.

The vulnerability requires no privileges and no user interaction, making it a prime target for automated exploitation campaigns and worm-like propagation.

A successful exploit results in complete confidentiality breach (data exposure), with a CVSS base score of 7.6.

CVSS v3.1 Vector Breakdown

Exploitability
Attack VectorAdjacent
Attack ComplexityLow
Privileges Req.None
User InteractionNone
ScopeUnchanged
Impact
ConfidentialityHigh
IntegrityLow
AvailabilityLow
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

Affected Vendors & Products

idec7 product(s)
microsmart fc6a firmwaremicrosmart fc6amicrosmart plus fc6a firmwaremicrosmart plus fc6adata file managerwindeditwindldr
Source: NVD CPE · 7 total CPE entries

Exploit & PoC Resources

NO KNOWN EXPLOITNo public exploit confirmed at this time
External links open in a new tab. Always verify in a controlled environment before use.

Official Patches & Advisories

All References (4)

Quick Facts

CVE IDCVE-2021-20826
CVSS Score7.6 / 10
SeverityHIGH
WeaknessCWE-522
CISA KEVNo
Affected1 vendor(s)
PublishedDec 24, 2021

Related CVEs (CWE-522)

Recommended Actions

  • Apply vendor patches immediately
  • Monitor CVE-2021-20826 in threat intel feeds
  • Review IDS/IPS signatures for exploitation attempts
Data sourced from NVD (NIST), CISA KEV, and EPSS (FIRST). Analysis generated by CTIWatch. CVE data is provided under the NVD usage policy.