PT-2015-2586 · Rockwell Automation · Micrologix 1100+1

Ilya Karpov

·

Published

2015-10-28

·

Updated

2015-10-28

·

CVE-2015-6486

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Micrologix 1100 versions before B FRN 15.000 Micrologix 1400 versions before B FRN 15.003
Description The issue is related to a lack of protection against SQL query structure attacks. Exploitation of this issue may allow a remote attacker to execute arbitrary SQL commands, potentially leading to the creation or deletion of accounts, or the elevation of privileges of existing accounts.
Recommendations For Micrologix 1100 versions before B FRN 15.000, update to a version B FRN 15.000 or later. For Micrologix 1400 versions before B FRN 15.003, update to a version B FRN 15.003 or later. As a temporary workaround, consider restricting access to the SQL query functionality to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-11951
BDU:2016-01724
CVE-2015-6486

Affected Products

Micrologix 1100
Micrologix 1400