PT-2015-2583 · Allen Bradley · Micrologix 1400+1
Published
2015-10-28
·
Updated
2015-10-28
·
CVE-2015-6491
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Allen-Bradley MicroLogix 1100 versions before B FRN 15.000
Allen-Bradley MicroLogix 1400 versions before B FRN 15.003
Description
The issue is related to a lack of restrictions on file uploads in the programmable logic controllers MicroLogix 1100 and 1400. This allows a remote authenticated user to insert the content of an arbitrary file into a FRAME element.
Recommendations
For Allen-Bradley MicroLogix 1100 versions before B FRN 15.000, update to version B FRN 15.000 or later.
For Allen-Bradley MicroLogix 1400 versions before B FRN 15.003, update to version B FRN 15.003 or later.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Micrologix 1100
Micrologix 1400