PT-2021-19975 · Rockwell Automation · Micro800+1
Adeen Ayub
+2
·
Published
2021-06-03
·
Updated
2022-10-25
·
CVE-2021-32926
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Micro800 versions All
MicroLogix 1400 versions 21 and later
Description
This issue allows an attacker to intercept and replace a legitimate new password hash with an illegitimate one during an authenticated password change request. This results in a denial-of-service condition, where the user can no longer authenticate to the controller.
Recommendations
For Micro800, to resolve the issue, update to a version that includes the fix for this problem, however, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For MicroLogix 1400 versions 21 and later, consider applying configuration changes or workarounds to minimize the risk of exploitation, however, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Micro800
Micrologix 1400