HIGH🇵🇱 Wersja polska

CVE-2021-32926

CVSS 7.5v3.1pub. 2021-06-03upd. 2026-06-04

When an authenticated password change request takes place, this vulnerability could allow the attacker to intercept the message that includes the legitimate, new password hash and replace it with an illegitimate hash. The user would no longer be able to authenticate to the controller (Micro800: All versions, MicroLogix 1400: Version 21 and later) causing a denial-of-service condition

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Rockwellautomation Micro800

    HW
    Rockwellautomation
    all versions
  • Rockwellautomation Micro800 Firmware

    OS
    Rockwellautomation
    all versions
  • Rockwellautomation Micrologix 1400

    HW
    Rockwellautomation
    all versions
  • Rockwellautomation Micrologix 1400 Firmware

    OS
    Rockwellautomation
    ≥ 21.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2020-6990CRITICAL9.8PL ✓same product

Hardkodowany klucz kryptograficzny w sterownikach Rockwell Automation MicroLogix

CVE-2017-14465CRITICAL9.8PL ✓same product

Nieautoryzowany dostęp do plików danych i logiki PLC w Allen Bradley MicroLogix 1400

CVE-2017-14462CRITICAL9.8PL ✓same product

Brak kontroli dostępu w Allen Bradley Micrologix 1400 – zapis bez uwierzytelnienia

CVE-2017-14463CRITICAL9.8PL ✓same product

Brak kontroli dostępu w Allen Bradley MicroLogix 1400 — nieautoryzowany odczyt/zapis

CVE-2017-14464CRITICAL9.8PL ✓same product

Podatność access control w sterowniku Allen Bradley MicroLogix 1400 Series B