Back to Database
Status published
Critical
CVE-2024-28751
ifm: Hardcoded telnet credentials in Smart PLC
Vulnerability Description
An high privileged remote attacker can enable telnet access that accepts hardcoded credentials.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-28751
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Logan Carpenter
- Dragos
More from ifm
View All →CVE-2024-5404
ifm: moneo prone to weak password recovery mechanism
Critical
9.8
CVE-2024-28750
ifm: Deleting function in Smart PLC allows command injections
High
7.2
CVE-2024-28749
ifm: Writing file function in Smart PLC allows command injections
High
7.2
CVE-2024-28748
ifm: Reading function in Smart PLC allows command injections
High
7.2
CVE-2024-28747
ifm: Use of Hard-coded Credentials
Critical
9.8
Affected Vendor
Affected Software
Smart PLC AC14xx Firmware, Smart PLC AC4xxS Firmware
Vulnerable Versions:
0
Timeline
Official Publish:
July 9th, 2024
Last Modified:
August 22nd, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H