CVE-2021-32926: High severity rockwellautomation Micro800 Firmware vulnerability
When an authenticated password change request takes place, this vulnerability could allow the attacker to intercept the message that includes the legitimate, new password hash and replace it with an illegitimate hash. The user would no longer be able to authenticate to the controller (Micro800: All versions, MicroLogix 1400: Version 21 and later) causing a denial-of-service condition
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-32926?
CVE-2021-32926 is a vulnerability that allows an attacker to intercept and replace the legitimate password hash during an authenticated password change request.
What is the severity of CVE-2021-32926?
CVE-2021-32926 has a severity rating of 7.5 (high).
Which software is affected by CVE-2021-32926?
The Rockwellautomation Micro800 Firmware and Rockwellautomation Micrologix 1400 Firmware are affected by CVE-2021-32926.
How can an attacker exploit CVE-2021-32926?
An attacker can exploit CVE-2021-32926 by intercepting the password change request and replacing the legitimate password hash with an illegitimate one.
Is Rockwellautomation Micro800 vulnerable to CVE-2021-32926?
Yes, Rockwellautomation Micro800 Firmware is vulnerable to CVE-2021-32926.