CVE-2017-12088: Input Validation
An exploitable denial of service vulnerability exists in the Ethernet functionality of the Allen Bradley Micrologix 1400 Series B FRN 21.2 and below. A specially crafted packet can cause a device power cycle resulting in a fault state and deletion of ladder logic. An attacker can send one unauthenticated packet to trigger this vulnerability
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-12088?
CVE-2017-12088 is a denial of service vulnerability in the Ethernet functionality of the Allen Bradley Micrologix 1400 Series B FRN 21.2 and below.
How severe is CVE-2017-12088?
CVE-2017-12088 has a severity rating of 7.5 out of 10 (high).
What software version is affected by CVE-2017-12088?
The Allen Bradley Micrologix 1400 Series B FRN version 21.2 and below is affected by CVE-2017-12088.
What is the impact of CVE-2017-12088?
An attacker can send a specially crafted packet that causes the device to power cycle, resulting in a fault state and deletion of ladder logic.
Is the Rockwellautomation Micrologix 1400 vulnerable to CVE-2017-12088?
No, the Rockwellautomation Micrologix 1400 is not vulnerable to CVE-2017-12088.
How do I fix CVE-2017-12088?
There is currently no known fix for CVE-2017-12088, it is recommended to contact the vendor for further assistance.