Synopsis
It is possible to obtain the Web Password Status of a Modicon PLC using an SNMP Get Request.
Description
The Modicon Quantum, Premium and Momentum brands of PLC's have a private SNMP MIB that is available on the Internet. The Web Password Status has been obtained via an SNMP Get Request. The Web Password Status is either enabled or disabled.
A Web Password Status of disabled identifies a vulnerability.
Solution
Change default community strings to a value not easily guessed and filter access to the SNMP port.
Plugin Details
File Name: scada_modicon_snmp_webpassword_status.nbin
Supported Sensors: Nessus
Vulnerability Information
Required KB Items: SNMP/community, SCADA/Device/Modicon