PT-2015-2583 · Allen Bradley · Micrologix 1400+1
Publicado
2015-10-28
·
Atualizado
2015-10-28
·
CVE-2015-6491
CVSS v2.0
4.0
Média
| Vetor | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Allen-Bradley MicroLogix 1100 versions before B FRN 15.000
Allen-Bradley MicroLogix 1400 versions before B FRN 15.003
Description
The issue is related to a lack of restrictions on file uploads in the programmable logic controllers MicroLogix 1100 and 1400. This allows a remote authenticated user to insert the content of an arbitrary file into a FRAME element.
Recommendations
For Allen-Bradley MicroLogix 1100 versions before B FRN 15.000, update to version B FRN 15.000 or later.
For Allen-Bradley MicroLogix 1400 versions before B FRN 15.003, update to version B FRN 15.003 or later.
Correção
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Micrologix 1100
Micrologix 1400