CVE-2018-17924: High severity rockwellautomation Micrologix 1400 Firmware vulnerability

Published Dec 7, 2018
·
Updated

Rockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unauthenticated, remote threat actor could send a CIP connection request to an affected device, and upon successful connection, send a new IP configuration to the affected device even if the controller in the system is set to Hard RUN mode. When the affected device accepts this new IP configuration, a loss of communication occurs between the device and the rest of the system as the system traffic is still attempting to communicate with the device via the overwritten IP address.

Affected Software

64 affected components
rockwellautomation Micrologix 1400 Firmware
rockwellautomation Micrologix 1400
rockwellautomation 1756-enbt Firmware
rockwellautomation 1756-enbt
rockwellautomation 1756-eweb Series A Firmware
rockwellautomation 1756-eweb Series A
rockwellautomation 1756-eweb Series B Firmware
rockwellautomation 1756-eweb Series B
rockwellautomation 1756-en2f Series A Firmware
rockwellautomation 1756-en2f Series A
rockwellautomation 1756-en2f Series B Firmware
rockwellautomation 1756-en2f Series B
rockwellautomation 1756-en2f Series C Firmware<=10.10
rockwellautomation 1756-en2f Series C
rockwellautomation 1756-en2t Series A Firmware
rockwellautomation 1756-en2t Series A
rockwellautomation 1756-en2t Series B Firmware
rockwellautomation 1756-en2t Series B
rockwellautomation 1756-en2t Series C Firmware
rockwellautomation 1756-en2t Series C
rockwellautomation 1756-en2t Series D Firmware<=10.10
rockwellautomation 1756-en2t Series D
rockwellautomation 1756-en2tr Series A Firmware
rockwellautomation 1756-en2tr Series A
rockwellautomation 1756-en2tr Series B Firmware
rockwellautomation 1756-en2tr Series B
rockwellautomation 1756-en2tr Series C Firmware<=10.10
rockwellautomation 1756-en2tr Series C
rockwellautomation 1756-en3tr Series A Firmware
rockwellautomation 1756-en3tr Series A
rockwellautomation 1756-en3tr Series B Firmware<=10.10
rockwellautomation 1756-en3tr Series B
All of the following
rockwellautomation Micrologix 1400 Firmware
rockwellautomation Micrologix 1400
All of the following
rockwellautomation 1756-enbt Firmware
rockwellautomation 1756-enbt
All of the following
rockwellautomation 1756-eweb Series A Firmware
rockwellautomation 1756-eweb Series A
All of the following
rockwellautomation 1756-eweb Series B Firmware
rockwellautomation 1756-eweb Series B
All of the following
rockwellautomation 1756-en2f Series A Firmware
rockwellautomation 1756-en2f Series A
All of the following
rockwellautomation 1756-en2f Series B Firmware
rockwellautomation 1756-en2f Series B
All of the following
rockwellautomation 1756-en2f Series C Firmware<=10.10
rockwellautomation 1756-en2f Series C
All of the following
rockwellautomation 1756-en2t Series A Firmware
rockwellautomation 1756-en2t Series A
All of the following
rockwellautomation 1756-en2t Series B Firmware
rockwellautomation 1756-en2t Series B
All of the following
rockwellautomation 1756-en2t Series C Firmware
rockwellautomation 1756-en2t Series C
All of the following
rockwellautomation 1756-en2t Series D Firmware<=10.10
rockwellautomation 1756-en2t Series D
All of the following
rockwellautomation 1756-en2tr Series A Firmware
rockwellautomation 1756-en2tr Series A
All of the following
rockwellautomation 1756-en2tr Series B Firmware
rockwellautomation 1756-en2tr Series B
All of the following
rockwellautomation 1756-en2tr Series C Firmware<=10.10
rockwellautomation 1756-en2tr Series C
All of the following
rockwellautomation 1756-en3tr Series A Firmware
rockwellautomation 1756-en3tr Series A
All of the following
rockwellautomation 1756-en3tr Series B Firmware<=10.10
rockwellautomation 1756-en3tr Series B

Event History

Dec 7, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Data Sourced
via NVD·02:29 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2018-17924?

CVE-2018-17924 is a vulnerability that affects Rockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules.

2

How does CVE-2018-17924 impact Rockwell Automation devices?

CVE-2018-17924 allows an unauthenticated remote attacker to send a new IP configuration to affected devices even if the controller is non-configurable.

3

What is the severity of CVE-2018-17924?

CVE-2018-17924 has a severity score of 8.6 (high).

4

Is CVE-2018-17924 exploitable remotely?

Yes, CVE-2018-17924 can be exploited remotely by an unauthenticated threat actor.

5

How can I mitigate the vulnerability CVE-2018-17924?

Apply the appropriate security patches and updates provided by Rockwell Automation to address CVE-2018-17924.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203