CVE-2026-3869
This vulnerability is an incorrect implementation of an authentication algorithm in PLCs. It can allow attackers to bypass authentication and gain unauthorized access, potentially compromising the device’s confidentiality, integrity, and availability.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Industrial PLCs that use the vulnerable authentication algorithm, typically found in manufacturing plants, utilities, and other critical infrastructure operators.
Real-world impact
An attacker could log in without credentials, modify or delete PLC settings, disrupt operations, or cause equipment damage.
Why this severity
The CVSS score of 9.2 reflects that the flaw is network‑reachable, requires no user interaction or privileges, and can lead to complete loss of confidentiality, integrity, and availability. The combination of high impact and low effort makes it critical.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources