First published: Wed Oct 28 2015(Updated: )
Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allow remote attackers to cause a denial of service (memory corruption and device crash) via a crafted HTTP request.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Rockwell Automation MicroLogix 1100 Firmware | <=14.000 | |
Rockwell Automation MicroLogix 1400 | <=15.002 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6492 has a severity level classified as critical due to its potential to cause a denial of service.
To mitigate CVE-2015-6492, upgrade the affected Allen-Bradley MicroLogix 1100 devices to firmware version B FRN 15.000 or later, and MicroLogix 1400 devices to version B FRN 15.003 or later.
CVE-2015-6492 affects Allen-Bradley MicroLogix 1100 devices with firmware versions prior to B FRN 15.000 and MicroLogix 1400 devices with versions prior to B FRN 15.003.
CVE-2015-6492 can facilitate a denial of service attack leading to memory corruption and potential device crashes.
Yes, CVE-2015-6492 is exploitable remotely through a crafted HTTP request.