PT-2015-3315 · Rockwell Automation · Micrologix 1400+1

Ilya Karpov

·

Published

2015-06-11

·

Updated

2017-03-16

·

CVE-2016-9338

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Rockwell Automation Allen-Bradley MicroLogix 1100 controller versions prior to 14.000 Rockwell Automation Micrologix 1400 (affected versions not specified)
Description The issue is related to an Incorrect Permission Assignment for Critical Resource in the Rockwell Automation Allen-Bradley MicroLogix 1100 controller and Rockwell Automation Micrologix 1400. This allows users with administrator privileges to remove all administrative users, requiring a factory reset to restore ancillary web server function. Exploitation of this vulnerability will still allow the affected device to function as a controller. The vulnerability is also related to insufficient access control, which can be exploited by an attacker with administrator privileges to delete all administrators, disabling additional device functions until a factory reset is performed.
Recommendations For Rockwell Automation Allen-Bradley MicroLogix 1100 controller versions prior to 14.000: Consider restricting access to the device to prevent unauthorized users from gaining administrator privileges. For Rockwell Automation Micrologix 1400: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02214
CVE-2016-9338

Affected Products

Micrologix 1100
Micrologix 1400