Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Pranita Binnar

Researcher fromVeermata Jijabai Technological Institute (VJTI)
#40120of 53,635
6.8Total CVSS
Vulnerabilities · 1
PT-2022-4950
6.8
2022-07-07
Rockwell Automation · Micrologix 1100/1400 · CVE-2022-2179
**Name of the Vulnerable Software and Affected Versions** Rockwell Automation MicroLogix 1100/1400 versions 21.007 and prior **Description** The issue is related to the X-Frame-Options header not being configured in the HTTP response, which could allow clickjacking attacks. This could enable a remote attacker to gain unauthorized access to protected information using a specially crafted link. The vulnerability is associated with incorrect restriction of visualized layers of the user interface. **Recommendations** For versions 21.007 and prior, consider configuring the X-Frame-Options header in the HTTP response to prevent clickjacking attacks. As a temporary workaround, restrict access to sensitive information and user interfaces to minimize the risk of exploitation.