CVE-2012-6440: Rockwell Automation ControlLogix PLC Improper Input Validation
The Web server password authentication mechanism used by the products is vulnerable to a MitM and Replay attack. Successful exploitation of this vulnerability will allow unauthorized access of the product’s Web server to view and alter product configuration and diagnostics information.
Rockwell Automation EtherNet/IP products; 1756-ENBT, 1756-EWEB, 1768-ENBT, and 1768-EWEB communication modules; CompactLogix L32E and L35E controllers; 1788-ENBT FLEXLogix adapter; 1794-AENTR FLEX I/O EtherNet/IP adapter; ControlLogix 18 and earlier; CompactLogix 18 and earlier; GuardLogix 18 and earlier; SoftLogix 18 and earlier; CompactLogix controllers 19 and earlier; SoftLogix controllers 19 and earlier; ControlLogix controllers 20 and earlier; GuardLogix controllers 20 and earlier; and MicroLogix 1100 and 1400
Other sources
The web-server password-authentication functionality in Rockwell Automation EtherNet/IP products; 1756-ENBT, 1756-EWEB, 1768-ENBT, and 1768-EWEB communication modules; CompactLogix L32E and L35E controllers; 1788-ENBT FLEXLogix adapter; 1794-AENTR FLEX I/O EtherNet/IP adapter; ControlLogix 18 and earlier; CompactLogix 18 and earlier; GuardLogix 18 and earlier; SoftLogix 18 and earlier; CompactLogix controllers 19 and earlier; SoftLogix controllers 19 and earlier; ControlLogix controllers 20 and earlier; GuardLogix controllers 20 and earlier; and MicroLogix 1100 and 1400 allows man-in-the-middle attackers to conduct replay attacks via HTTP traffic.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2012-6440?
CVE-2012-6440 has a high severity rating due to its potential impact on unauthorized access to sensitive systems.
How do I fix CVE-2012-6440?
To mitigate CVE-2012-6440, ensure that you apply the latest firmware updates provided by Rockwell Automation for affected products.
Which products are affected by CVE-2012-6440?
CVE-2012-6440 affects several Rockwell Automation EtherNet/IP communication modules and controllers, including ControlLogix and CompactLogix models.
What kind of vulnerabilities does CVE-2012-6440 represent?
CVE-2012-6440 represents a vulnerability in the password-authentication functionality of specific Rockwell Automation products.
Is my system vulnerable if I use Rockwell Automation products?
If you are using the specified models and firmware versions listed in CVE-2012-6440, your system may be vulnerable.