PT-2016-6612 · Rockwell Automation · Micrologix 1400 Plc

Publicado

2016-08-24

·

Atualizado

2016-11-28

·

CVE-2016-5645

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Rockwell Automation MicroLogix 1400 PLC versions 1766-L32BWA, 1766-L32AWA, 1766-L32BXB, 1766-L32BWAA, 1766-L32AWAA, 1766-L32BXBA
Description The issue concerns a hardcoded SNMP community in the affected devices, making it easier for remote attackers to load arbitrary firmware updates by leveraging knowledge of this community.
Recommendations For versions 1766-L32BWA, 1766-L32AWA, 1766-L32BXB, 1766-L32BWAA, 1766-L32AWAA, 1766-L32BXBA, consider changing the hardcoded SNMP community string to a unique and secure value to prevent unauthorized access. As a temporary workaround, restrict access to the SNMP service to minimize the risk of exploitation. Avoid using default or easily guessable community strings in the affected devices until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-5645

Produtos afetados

Micrologix 1400 Plc