CRITICAL🇵🇱 Wersja polska

CVE-2017-14463

CVSS 9.8v3.1pub. 2018-04-05upd. 2024-11-21

An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings, or modification of ladder logic. An attacker can send unauthenticated packets to trigger this vulnerability. Required Keyswitch State: REMOTE or PROG Associated Fault Code: 0012 Fault Type: Non-User Description: A fault state can be triggered by overwriting the ladder logic data file (type 0x22 number 0x02) with null values.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Rockwellautomation Micrologix 1400

    HW
    Rockwellautomation
    all versions
  • Rockwellautomation Micrologix 1400 B Firmware

    OS
    Rockwellautomation
    ≤ 21.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2020-6990CRITICAL9.8PL ✓same product

Hardkodowany klucz kryptograficzny w sterownikach Rockwell Automation MicroLogix

CVE-2017-14466CRITICAL9.8PL ✓same product

Błąd kontroli dostępu w Allen Bradley Micrologix 1400 — nadpisanie hasła głównego

CVE-2017-14462CRITICAL9.8PL ✓same product

Brak kontroli dostępu w Allen Bradley Micrologix 1400 – zapis bez uwierzytelnienia

CVE-2017-14464CRITICAL9.8PL ✓same product

Podatność access control w sterowniku Allen Bradley MicroLogix 1400 Series B

CVE-2017-14465CRITICAL9.8PL ✓same product

Nieautoryzowany dostęp do plików danych i logiki PLC w Allen Bradley MicroLogix 1400