CVE-2014-5410: Rockwell Automation Micrologix 1400 Improper Input Validation
The DNP3 feature on Rockwell Automation Allen-Bradley MicroLogix 1400 1766-Lxxxxx A FRN controllers 7 and earlier and 1400 1766-Lxxxxx B FRN controllers before 15.001 allows remote attackers to cause a denial of service (process disruption) via malformed packets over (1) an Ethernet network or (2) a serial line.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5410?
The severity of CVE-2014-5410 is high due to its potential to cause denial of service on affected Rockwell Automation MicroLogix controllers.
How do I fix CVE-2014-5410?
To fix CVE-2014-5410, update the firmware of the affected MicroLogix controllers to version 15.001 or later.
What systems are affected by CVE-2014-5410?
CVE-2014-5410 affects Rockwell Automation Allen-Bradley MicroLogix 1400 controllers with firmware versions before 15.001.
What kind of attack does CVE-2014-5410 facilitate?
CVE-2014-5410 facilitates remote denial of service attacks via malformed packets on Ethernet networks.
Is CVE-2014-5410 related to remote access vulnerabilities?
Yes, CVE-2014-5410 allows for remote attacks which can lead to process disruption on affected devices.