CVE-2017-12093: Medium severity rockwell automation micrologix 1400 vulnerability
An exploitable insufficient resource pool vulnerability exists in the session communication functionality of Allen Bradley Micrologix 1400 Series B Firmware 21.2 and before. A specially crafted stream of packets can cause a flood of the session resource pool resulting in legitimate connections to the PLC being disconnected. An attacker can send unauthenticated packets to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-12093?
CVE-2017-12093 is an exploitable insufficient resource pool vulnerability in the session communication functionality of Allen Bradley Micrologix 1400 Series B Firmware 21.2 and before.
How does CVE-2017-12093 affect Rockwell Automation Micrologix 1400 B Firmware?
CVE-2017-12093 affects Rockwell Automation Micrologix 1400 B Firmware version 21.2 and before.
What is the severity of CVE-2017-12093?
CVE-2017-12093 has a severity score of 5.3, which is classified as medium.
How can CVE-2017-12093 be exploited?
CVE-2017-12093 can be exploited by sending a specially crafted stream of packets that can cause a flood of the session resource pool, resulting in legitimate connections being affected.
Is Rockwell Automation Micrologix 1400 vulnerable to CVE-2017-12093?
Rockwell Automation Micrologix 1400 is vulnerable to CVE-2017-12093 if it is running firmware version 21.2 or earlier.