First published: Wed Oct 28 2015(Updated: )
Cross-site scripting (XSS) vulnerability in the web server on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Rockwell Automation MicroLogix 1100 Firmware | <=14.000 | |
Rockwell Automation MicroLogix 1400 | <=15.002 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6488 is classified as a medium severity cross-site scripting vulnerability.
To mitigate CVE-2015-6488, update your Allen-Bradley MicroLogix 1100 devices to firmware version B FRN 15.000 or higher, and MicroLogix 1400 devices to B FRN 15.003 or higher.
CVE-2015-6488 affects Allen-Bradley MicroLogix 1100 devices with firmware before B FRN 15.000 and MicroLogix 1400 devices with firmware before B FRN 15.003.
CVE-2015-6488 can allow remote attackers to inject arbitrary web scripts or HTML into web pages served by the vulnerable devices.
Currently, the best recommendation is to upgrade the firmware of affected devices to the latest versions to eliminate the vulnerability.