PT-2021-19975 · Rockwell Automation · Micro800+1

Adeen Ayub

+2

·

Published

2021-06-03

·

Updated

2022-10-25

·

CVE-2021-32926

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Micro800 versions All MicroLogix 1400 versions 21 and later
Description This issue allows an attacker to intercept and replace a legitimate new password hash with an illegitimate one during an authenticated password change request. This results in a denial-of-service condition, where the user can no longer authenticate to the controller.
Recommendations For Micro800, to resolve the issue, update to a version that includes the fix for this problem, however, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For MicroLogix 1400 versions 21 and later, consider applying configuration changes or workarounds to minimize the risk of exploitation, however, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2021-32926

Affected Products

Micro800
Micrologix 1400