PT-2015-3356 · Rockwell Automation · Micrologix 1400+1
Ilya Karpov
·
Published
2015-10-27
·
Updated
2019-10-03
·
CVE-2017-7899
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers versions 16.00 and prior
Rockwell Automation Allen-Bradley MicroLogix 1400 programmable logic controllers versions 16.00 and prior
Description
An Information Exposure issue was discovered where user credentials are sent to the web server using the HTTP GET method, which may result in the credentials being logged. This could make user credentials available for unauthorized retrieval. The vulnerability is related to the transmission of user credentials to the web server, potentially allowing a remote attacker to obtain user credentials.
Recommendations
For Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers versions 16.00 and prior, consider disabling the HTTP GET method for transmitting user credentials until a patch is available.
For Rockwell Automation Allen-Bradley MicroLogix 1400 programmable logic controllers versions 16.00 and prior, consider disabling the HTTP GET method for transmitting user credentials until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Micrologix 1100
Micrologix 1400