CVE-2012-4690: High severity rockwell automation micrologix vulnerability
Rockwell Automation Allen-Bradley MicroLogix controller 1100, 1200, 1400, and 1500; SLC 500 controller platform; and PLC-5 controller platform, when Static status is not enabled, allow remote attackers to cause a denial of service via messages that trigger modification of status bits.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4690?
CVE-2012-4690 is classified as a denial of service vulnerability.
How do I fix CVE-2012-4690?
To fix CVE-2012-4690, ensure that the Static status is enabled on the affected Rockwell Automation controllers.
Which devices are affected by CVE-2012-4690?
CVE-2012-4690 affects Rockwell Automation MicroLogix 1100, 1200, 1400, 1500, SLC 500, and PLC-5 controllers.
What kind of attack is possible with CVE-2012-4690?
An attacker can perform a denial of service attack by sending specific messages that modify status bits on the affected controllers.
Is there any workaround for CVE-2012-4690?
The main workaround for CVE-2012-4690 is to enable the Static status on the controllers to mitigate the risk.