Modicon PLC Embedded HTTP Server Detection

medium Nessus Plugin ID 23820

Synopsis

The host is a Modicon PLC with an embedded HTTP server used for configuration or monitoring.

Description

The Modicon Quantum, Premium and Micro models of PLC have an HTTP server interface. The Modicon PLC web server and content was identified on the host.

Solution

Restrict access to TCP port 80 to authorized management addresses.

Plugin Details

Severity: Medium

ID: 23820

File Name: scada_modicon_decorum_http_detect.nbin

Version: 1.89

Type: remote

Family: SCADA

Published: 12/11/2006

Updated: 3/19/2024

Asset Inventory: true

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N