CVE-2021-33012: Input Validation
Rockwell Automation MicroLogix 1100, all versions, allows a remote, unauthenticated attacker sending specially crafted commands to cause the PLC to fault when the controller is switched to RUN mode, which results in a denial-of-service condition. If successfully exploited, this vulnerability will cause the controller to fault whenever the controller is switched to RUN mode.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-33012.
What is the severity of CVE-2021-33012?
The severity of CVE-2021-33012 is high with a severity value of 8.6.
How does CVE-2021-33012 affect Rockwell Automation MicroLogix 1100?
CVE-2021-33012 allows a remote unauthenticated attacker to send specially crafted commands to cause a denial-of-service condition on the MicroLogix 1100 when it is switched to RUN mode.
How can CVE-2021-33012 be exploited?
CVE-2021-33012 can be exploited by sending specially crafted commands to the MicroLogix 1100 controller when it is in RUN mode.
Is Rockwell Automation MicroLogix 1100 firmware affected by CVE-2021-33012?
Yes, Rockwell Automation MicroLogix 1100 firmware is affected by CVE-2021-33012.