PT-2015-3356 · Rockwell Automation · Micrologix 1400+1

Ilya Karpov

·

Published

2015-10-27

·

Updated

2019-10-03

·

CVE-2017-7899

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers versions 16.00 and prior Rockwell Automation Allen-Bradley MicroLogix 1400 programmable logic controllers versions 16.00 and prior
Description An Information Exposure issue was discovered where user credentials are sent to the web server using the HTTP GET method, which may result in the credentials being logged. This could make user credentials available for unauthorized retrieval. The vulnerability is related to the transmission of user credentials to the web server, potentially allowing a remote attacker to obtain user credentials.
Recommendations For Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers versions 16.00 and prior, consider disabling the HTTP GET method for transmitting user credentials until a patch is available. For Rockwell Automation Allen-Bradley MicroLogix 1400 programmable logic controllers versions 16.00 and prior, consider disabling the HTTP GET method for transmitting user credentials until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00258
CVE-2017-7899

Affected Products

Micrologix 1100
Micrologix 1400