Rockwell PLC5/SLC5/0x/RSLogix Credentials management
Published Mar 26, 2019
9.8
CRITICALCVSS 3.0
EPSS 5.70%
Description
The potential exists for exposure of the product's password used to restrict unauthorized access to Rockwell PLC5/SLC5/0x/RSLogix 1785-Lx and 1747-L5x controllers. The potential exists for an unauthorized programming and configuration client to gain access to the product and allow changes to the product’s configuration or program. When applicable, upgrade product firmware to a version that includes enhanced security functionality compatible with Rockwell Automation's FactoryTalk Security services.
Affected products
-
- Version 1747-L5xStatusaffectedConstraints-
- Version 1785-LxStatusaffectedConstraints-
- Version
-
-
- Version 1747-L5xStatusaffectedConstraints-
- Version 1785-LxStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Rockwell Automation | PLC5 | unaffected |
| |||||||||
| Rockwell Automation | RSLogix | unaffected |
| |||||||||
| Rockwell Automation | SLC5/0x | unaffected |
|
Configuration 1
- n/a
Configuration 2
- n/a
Running on/with
- n/a
Configuration 3
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
To help reduce the likelihood of exploitation and associated security risk, Rockwell Automation recommends the following immediate mitigation strategies (Note: multiple strategies are recommended to be employed simultaneously):
* For PLC-5 controllers, enable and configure "Passwords and Privileges" via RSLogix 5 configuration software to restrict access to critical data and improve overall password security. * When applicable, upgrade product firmware to a version that includes enhanced security functionality compatible with Rockwell Automation's FactoryTalk Security services. This functionality can be enabled via RSLogix 5 or RSLogix 500 software. (Consult Rockwell TechnoteRockwell Technote, http://rockwellautomation.custhelp.com/app/answers/detail/a_id/66678/kw/vulnerability/r_id/115100 , website last accessed January 12, 2010 for applicable firmware versions) * Use the latest version of RSLogix 5 or RSLogix 500 configuration software and enable FactoryTalk Security services. * Disable where possible the capability to perform remote programming and configuration of the product over a network to a controller by placing the controller's key switch into RUN mode. * For SLC controllers, enable static protection on all critical data table files to prevent any remote data changes to critical data. * Employ layered security and defense-in-depth methods in system design to restrict and control access to individual products and control networks. Refer to http://www.ab.com/networks/architectures.html for comprehensive information about implementing validated architectures designed to deliver these measures. * Block all traffic to the CSP, Ethernet/IP, or other CIP protocol-based devices from outside the Manufacturing Zone by restricting or blocking access to TCP and UDP Port 2222 and Port 44818 using appropriate security technology (e.g., a firewall, UTM devices, or other security device). * Restrict physical and electronic access to automation products, networks, and systems to only those individuals authorized to make changes to control system equipment. * Frequently change the product’s password and obsolete previously used passwords to reduceexposure to threat from a product password becoming known.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (21 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 5.70% (0.05695) | 92.77th | v5 (v2026.06.15) |
| Sep 22, 2026 | 5.70% (0.05695) | 92.66th | v5 (v2026.06.15) |
| Sep 21, 2026 | 8.90% (0.08898) | 95.05th | v5 (v2026.06.15) |
| Sep 6, 2026 | 5.70% (0.05695) | 92.50th | v5 (v2026.06.15) |
| Sep 5, 2026 | 8.90% (0.08898) | 94.94th | v5 (v2026.06.15) |
| Aug 30, 2026 | 5.70% (0.05695) | 92.46th | v5 (v2026.06.15) |
| Aug 28, 2026 | 8.90% (0.08898) | 94.91th | v5 (v2026.06.15) |
| Aug 24, 2026 | 5.70% (0.05695) | 92.42th | v5 (v2026.06.15) |
| Aug 23, 2026 | 8.90% (0.08898) | 94.89th | v5 (v2026.06.15) |
| Jun 15, 2026 | 5.70% (0.05695) | 91.99th | v5 (v2026.06.15) |
| Jun 27, 2025 | 1.41% (0.01414) | 79.61th | v4 (v2025.03.14) |
| Mar 30, 2025 | 9.38% (0.09385) | 92.03th | v4 (v2025.03.14) |
| Mar 29, 2025 | 13.11% (0.13105) | 90.15th | v4 (v2025.03.14) |
| Mar 17, 2025 | 9.38% (0.09385) | 92.20th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.17% (0.00167) | 54.80th | v3 (v2023.03.01) |
| Jul 10, 2024 | 0.17% (0.00172) | 54.51th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.17% (0.00172) | 52.47th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Sep 10, 2022 | 0.89% (0.00885) | 26.24th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.89% (0.00885) | 24.24th | v2 (v2022.01.01) |
| Feb 4, 2022 | 0.89% (0.00885) | 10.50th | v2 (v2022.01.01) |
References (3)
- http://rockwellautomation.custhelp.com/app/answers/detail/a_id/66684/kw/vulnerability/r_id/115100
- https://ics-cert.us-cert.gov/advisories/ICSA-10-070-02 MitigationThird Party AdvisoryUS Government Resource
- https://www.cisa.gov/news-events/ics-advisories/icsa-10-070-02 x_refsource_MISC
| Link | Providers | Tags |
|---|---|---|
| http://rockwellautomation.custhelp.com/app/answers/detail/a_id/66684/kw/vulnerability/r_id/115100 | ||
| https://ics-cert.us-cert.gov/advisories/ICSA-10-070-02 | MitigationThird Party AdvisoryUS Government Resource | |
| https://www.cisa.gov/news-events/ics-advisories/icsa-10-070-02 | x_refsource_MISC |
Change history (0)
No recorded changes yet.