PT-2018-5663 · Allen Bradley · Allen Bradley Micrologix 1400 Series B

Published

2018-04-05

·

Updated

2022-12-14

·

CVE-2017-14468

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Allen Bradley Micrologix 1400 Series B versions 21.2 and before
Description: The issue concerns an access control vulnerability in the data, program, and function file permissions functionality. This vulnerability can be exploited by sending specially crafted packets, which can result in the disclosure of sensitive information, modification of settings, or modification of ladder logic. An attacker can trigger this issue by sending unauthenticated packets. The vulnerability is leveraged in a larger exploit to flash custom firmware, and it requires the Key Switch State to be either REMOTE or PROG.
Recommendations: For Allen Bradley Micrologix 1400 Series B versions 21.2 and before, consider restricting access to the device when the Key Switch State is set to REMOTE or PROG to minimize the risk of exploitation. As a temporary workaround, limit the ability to send unauthenticated packets to the device until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2017-14468

Affected Products

Allen Bradley Micrologix 1400 Series B