First published: Thu Apr 05 2018(Updated: )
An exploitable insufficient resource pool vulnerability exists in the session communication functionality of Allen Bradley Micrologix 1400 Series B Firmware 21.2 and before. A specially crafted stream of packets can cause a flood of the session resource pool resulting in legitimate connections to the PLC being disconnected. An attacker can send unauthenticated packets to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rockwellautomation Micrologix 1400 B Firmware | <=21.2 | |
Rockwellautomation Micrologix 1400 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-12093 is an exploitable insufficient resource pool vulnerability in the session communication functionality of Allen Bradley Micrologix 1400 Series B Firmware 21.2 and before.
CVE-2017-12093 affects Rockwell Automation Micrologix 1400 B Firmware version 21.2 and before.
CVE-2017-12093 has a severity score of 5.3, which is classified as medium.
CVE-2017-12093 can be exploited by sending a specially crafted stream of packets that can cause a flood of the session resource pool, resulting in legitimate connections being affected.
Rockwell Automation Micrologix 1400 is vulnerable to CVE-2017-12093 if it is running firmware version 21.2 or earlier.