Security vulnerabilities are often leveraged by cybercriminals determined to make the most of lower staffing levels and existing network issues. Topping this years Christmas hit list are three flaws that, if left unchecked, pose a serious risk for enterprises. Schneider Electric’s Modicon M340 programmable logic controller (PLC) products are affected by CVE-2015-7937, a buffer overflow that occurs when a random password of 90 to 100 characters is entered into the PLC’s Web server access point.”]

