Lenze PLC Designer V4 Password Exposure Vulnerability in c430, c520, and c550 Controllers

Vulnerability

A vulnerability in Lenze PLC Designer V4, specifically in version 4.0.0, allows local, low-privileged attackers to view the passwords of connected controllers in plain text. This issue arises from an improper implementation that exposes passwords under certain conditions, but only in the software interface, not on the devices themselves. The vulnerability is limited to use with c430, c520, and c550 controllers.

Impact

Exploitation of this vulnerability could lead to unauthorized exposure of passwords in plain text within the PLC Designer V4 interface. This could allow individuals with access to the engineering workstation to view sensitive credentials. However, it does not affect password management on the controllers themselves.

Remediation

Users are strongly advised to update to PLC Designer V4 version 4.0.1, where this vulnerability has been fixed. Lenze also recommends using the tool only in closed and protected security zones to prevent unauthorized viewing of passwords during entry.

Added: Jun 25, 2025, 10:36 AM
Updated: Jun 25, 2025, 10:36 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.3
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.