Metrics
Affected Vendors & Products
No advisories yet.
Solution
Horner Automation recommends users update to Cscape v10.2 SP2 or later. Horner Automation has also released the latest firmware for both XL4 and XL7 PLCs. Horner recommends users update to the latest version of the firmware. https://hornerautomation.com/cscape-software-free/cscape-software/
Workaround
No workaround given by the vendor.
Fri, 17 Apr 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to systems and services. The limited password complexity and no password input limiters makes brute force password enumeration possible. | |
| Title | Horner Automation Cscape and XL4, XL7 PLC Weak password requirements | |
| Weaknesses | CWE-521 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-04-17T15:14:06.346Z
Reserved: 2026-04-14T15:07:32.676Z
Link: CVE-2026-6284
No data.
Status : Received
Published: 2026-04-17T16:17:07.620
Modified: 2026-04-17T16:17:07.620
Link: CVE-2026-6284
No data.
OpenCVE Enrichment
No data.