CVE-2024-41927: Idec FT1A-b12ra Firmware

Medium severity, CVSS 4.6. EPSS: 0.2% chance of exploitation in the next 30 days.

Cleartext transmission of sensitive information vulnerability exists in multiple IDEC PLCs. If an attacker sends a specific command to PLC's serial communication port, user credentials may be obtained. As a result, the program of the PLC may be obtained, and the PLC may be manipulated.

Affected products

  • Idec FT1A-b12ra Firmware: up to and including 2.41
  • Idec FT1A-b24ra Firmware: up to and including 2.41
  • Idec FT1A-h12ra Firmware: up to and including 2.41
  • Idec FT1A-h12rc Firmware: up to and including 2.41
  • Idec FT1A-h24ra Firmware: up to and including 2.41
  • Idec FT1A-h24rc Firmware: up to and including 2.41
  • Idec FT1A-PC1 Firmware: up to and including 2.41
  • Idec FT1A-PC2 Firmware: up to and including 2.41
  • Idec FT1A-PC3 Firmware: up to and including 2.41
  • Idec FT1A-PM1 Firmware: up to and including 2.41
  • Idec FT9Z-1a01 Firmware: up to and including 2.41
  • Idec FT9Z-PSP1PN05 Firmware: up to and including 2.41
  • Idec HG9Z-XCM2A Firmware: up to and including 2.41
  • Idec Kit-FC6A-16-Kc Firmware: up to and including 2.60
  • Idec Kit-FC6A-16-Kd Firmware: up to and including 2.60
  • Idec Kit-FC6A-16-Pc Firmware: up to and including 2.6
  • Idec Kit-FC6A-16-Pd Firmware: up to and including 2.60
  • Idec Kit-FC6A-16-Ra-HG1G Firmware: up to and including 2.60
  • Idec Kit-FC6A-16-Ra-HG2G-5tn Firmware: up to and including 2.60
  • Idec Kit-FC6A-16-Ra-HG2G-5tt Firmware: up to and including 2.60
  • Idec Kit-FC6A-16-Ra Firmware: up to and including 2.60
  • Idec Kit-FC6A-16-Rc-HG1G Firmware: up to and including 2.60
  • Idec Kit-FC6A-16-Rc-HG2G-5tn Firmware: up to and including 2.60
  • Idec Kit-FC6A-16-Rc-HG2G-5tt Firmware: up to and including 2.60
  • Idec Kit-FC6A-16-Rc Firmware: up to and including 2.60
  • and 66 more

Published 2024-09-04. Last modified 2026-06-17.