CVE-2026-6284
9.1Horner Automation · Cscape, XL7 PLC, XL4 PLC
Horner Automation industrial control products are vulnerable to password brute-forcing due to weak complexity requirements and a lack of input rate limiting, potentially allowing unauthorized access.
Executive summary
A critical authentication weakness in multiple Horner Automation PLC products allows remote attackers to gain unauthorized access via brute-force password enumeration.
Vulnerability
The vulnerability stems from improper password complexity enforcement and the absence of account lockout mechanisms (CWE-521). This allows unauthenticated remote attackers to perform brute-force attacks against the PLC management interface to gain unauthorized system access.
Business impact
Successful exploitation grants an attacker unauthorized access to industrial control hardware, which could lead to operational disruption, loss of process integrity, or physical damage to controlled machinery. Given the CVSS score of 9.1, this represents a severe risk to operational technology (OT) environments where unauthorized command execution can have significant safety and financial consequences.
Remediation
Immediate Action: Update Cscape software to version 10.2 SP2 or later and apply the latest firmware updates for both XL4 and XL7 PLC units as provided by Horner Automation.
Proactive Monitoring: Monitor network traffic for repeated failed authentication attempts directed at PLC management interfaces and review system access logs for anomalous login activity.
Compensating Controls: Isolate affected PLCs behind robust network firewalls and restrict access to management interfaces to trusted administrative workstations only to prevent remote exploitation.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability presents a significant risk to industrial operations due to the ease with which attackers can compromise device credentials. Organizations utilizing these Horner Automation products must prioritize the firmware and software updates immediately to implement necessary password security controls and prevent unauthorized system access.