PT-2020-1766 · Rockwell Automation · Rslogix 500+2

Published

2020-03-05

·

Updated

2020-03-20

·

CVE-2020-6984

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Rockwell Automation MicroLogix 1400 Controllers Series B versions 21.001 and prior Rockwell Automation MicroLogix 1400 Controllers Series A all versions Rockwell Automation MicroLogix 1100 Controller all versions RSLogix 500 Software versions 12.001 and prior
Description The issue is related to a cryptographic function used to protect passwords in the affected software. This function has a discoverable weakness, potentially allowing a remote attacker to gain unauthorized access to confidential information, including passwords. The vulnerability is associated with the use of flawed cryptographic algorithms.
Recommendations For Rockwell Automation MicroLogix 1400 Controllers Series B versions 21.001 and prior, update to a version later than 21.001. For Rockwell Automation MicroLogix 1400 Controllers Series A all versions, consider disabling password protection until a patch is available. For Rockwell Automation MicroLogix 1100 Controller all versions, restrict access to the device to minimize the risk of exploitation. For RSLogix 500 Software versions 12.001 and prior, update to a version later than 12.001.

Fix

Use of a Broken Cryptographic Algorithm

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-01007
CVE-2020-6984

Affected Products

Micrologix 1100 Controller
Micrologix 1400 Controllers Series A
Rslogix 500