CVE-2026-6284 - Vulnerability Analysis
CriticalCVSS: 9.1Last Updated: April 20, 2026
PLC - Authentication Bypass
Overview
A PLC contains a broken authentication vulnerability caused by limited password complexity and lack of input limiters, letting attackers with network access brute force passwords to gain unauthorized access.
Severity & Score
Impact
Attackers can gain unauthorized access to systems and services by brute forcing passwords.
Mitigation
Implement stronger password complexity and input limiters or update to the latest secure version.
References
Social Media Activity(1 post)
⚠️ CRITICAL: Horner Automation Cscape and XL4, XL7 PLC Horner Automation Cscape v10.0, XL4 PLC v16.32.0, and XL7 PLC v15.60 contain a critical password brute-force vulnerability (CVE-2026-6284, CVSS 9.1) with no rate limiting. This affects manufacturing environments globally and allows unauthenticated network attackers to compromise PLCs controlling cr… https://threatnoir.com/focus #infosec #cybersecurity
View original postRelated Resources
Details
- CVE ID
- CVE-2026-6284
- Severity
- Critical
- CVSS Score
- 9.1
- Type
- broken_authentication
- Status
- unconfirmed
- EPSS
- 1.1%
- Social Posts
- 1
CWE
- CWE-521
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N