First published: Wed Oct 28 2015(Updated: )
SQL injection vulnerability on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Rockwell Automation MicroLogix 1100 Firmware | <=14.000 | |
Rockwell Automation MicroLogix 1400 | <=15.002 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6486 has a high severity due to its potential for remote code execution through SQL injection.
To fix CVE-2015-6486, update the MicroLogix 1100 devices to firmware version B FRN 15.000 or higher, and the MicroLogix 1400 devices to firmware version B FRN 15.003 or higher.
CVE-2015-6486 affects users of Allen-Bradley MicroLogix 1100 and 1400 devices running specific outdated firmware versions.
CVE-2015-6486 can be exploited to execute arbitrary SQL commands by authenticated remote users.
CVE-2015-6486 was disclosed in December 2015.