CRITICAL🇵🇱 Wersja polska

CVE-2017-14465

CVSS 9.8v3.1pub. 2018-04-05upd. 2024-11-21

An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings, or modification of ladder logic. An attacker can send unauthenticated packets to trigger this vulnerability. Required Keyswitch State: REMOTE Description: Any input or output can be forced, causing unpredictable activity from the PLC.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Rockwellautomation Micrologix 1400

    HW
    Rockwellautomation
    all versions
  • Rockwellautomation Micrologix 1400 B Firmware

    OS
    Rockwellautomation
    ≤ 21.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2020-6990CRITICAL9.8PL ✓same product

Hardkodowany klucz kryptograficzny w sterownikach Rockwell Automation MicroLogix

CVE-2017-14466CRITICAL9.8PL ✓same product

Błąd kontroli dostępu w Allen Bradley Micrologix 1400 — nadpisanie hasła głównego

CVE-2017-14462CRITICAL9.8PL ✓same product

Brak kontroli dostępu w Allen Bradley Micrologix 1400 – zapis bez uwierzytelnienia

CVE-2017-14463CRITICAL9.8PL ✓same product

Brak kontroli dostępu w Allen Bradley MicroLogix 1400 — nieautoryzowany odczyt/zapis

CVE-2017-14464CRITICAL9.8PL ✓same product

Podatność access control w sterowniku Allen Bradley MicroLogix 1400 Series B