Rockwell Automation ControlLogix PLC Improper Authentication
Published Jan 24, 2013
9.8
CRITICALCVSS 3.1
EPSS 7.85%
Description
The device does not properly authenticate users and the potential exists for a remote user to upload a new firmware image to the Ethernet card, whether it is a corrupt or legitimate firmware image. Successful exploitation of this vulnerability could cause loss of availability, integrity, and confidentiality and a disruption in communications with other connected devices.
Rockwell Automation EtherNet/IP products; 1756-ENBT, 1756-EWEB, 1768-ENBT, and 1768-EWEB communication modules; CompactLogix L32E and L35E controllers; 1788-ENBT FLEXLogix adapter; 1794-AENTR FLEX I/O EtherNet/IP adapter; ControlLogix 18 and earlier; CompactLogix 18 and earlier; GuardLogix 18 and earlier; SoftLogix 18 and earlier; CompactLogix controllers 19 and earlier; SoftLogix controllers 19 and earlier; ControlLogix controllers 20 and earlier; GuardLogix controllers 20 and earlier; and MicroLogix 1100 and 1400
Affected products
- Vendor Rockwell Automation Product 1756-ENBT, 1756-EWEB, 1768-ENBT, 1768-EWEB communication modules Defaultunaffected
- Version AllStatusaffectedConstraints-
- Version
-
- Version AllStatusaffectedConstraints-
- Version
-
- Version AllStatusaffectedConstraints-
- Version
-
- Version AllStatusaffectedConstraints-
- Version
-
- Version 0StatusaffectedConstraints<=19
- Version
-
- Version 0StatusaffectedConstraints<=20
- Version
- Vendor Rockwell Automation Product ControlLogix, CompactLogix, GuardLogix, and SoftLogix Defaultunaffected
- Version 0StatusaffectedConstraints<=18
- Version
-
- Version 1100StatusaffectedConstraints-
- Version 1400StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Rockwell Automation | 1756-ENBT, 1756-EWEB, 1768-ENBT, 1768-EWEB communication modules | unaffected |
| |||||||||
| Rockwell Automation | 1788-ENBT FLEXLogix adapter | unaffected |
| |||||||||
| Rockwell Automation | 1794-AENTR FLEX I/O EtherNet/IP adapter | unaffected |
| |||||||||
| Rockwell Automation | CompactLogix L32E and L35E controllers | unaffected |
| |||||||||
| Rockwell Automation | CompactLogix and SoftLogix controllers | unaffected |
| |||||||||
| Rockwell Automation | ControlLogix and GuardLogix controllers | unaffected |
| |||||||||
| Rockwell Automation | ControlLogix, CompactLogix, GuardLogix, and SoftLogix | unaffected |
| |||||||||
| Rockwell Automation | MicroLogix | unaffected |
|
- ≤ 20
- ≤ 20
- ≤ 1100
- ≤ 1400
- ≤ 19
- n/a
- n/a
- n/a
- n/a
- n/a
- ≤ 18
- ≤ 19
- n/a
- n/a
- ≤ 18
- n/a
- ≤ 18
- ≤ 18
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
According to Rockwell, any of the above products that become affected by a vulnerability can be reset by rebooting or power cycling the affected product. After the reboot, the affected product may require some reconfiguration.
To mitigate the vulnerabilities, Rockwell has developed and released security patches on July 18, 2012, to address each of the issues. To download and install the patches please refer to Rockwell’s Advisories at:
https://rockwellautomation.custhelp.com/app/answers/detail/a_id/470154 https://rockwellautomation.custhelp.com/app/answers/detail/aid/470155 https://rockwellautomation.custhelp.com/app/answers/detail/aid/470156
For more information on security with Rockwell Automation products, please refer to Rockwell’s Security Advisory Index http://rockwellautomation.custhelp.com/app/answers/detail/a_id/54102 .
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Jun 3, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (18 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 7.85% (0.07845) | 94.51th | v5 (v2026.06.15) |
| Aug 9, 2026 | 7.85% (0.07845) | 94.11th | v5 (v2026.06.15) |
| Jun 15, 2026 | 9.58% (0.09579) | 94.83th | v5 (v2026.06.15) |
| Jun 4, 2026 | 8.62% (0.08623) | 92.58th | v4 (v2025.03.14) |
| Nov 26, 2025 | 11.82% (0.11818) | 93.44th | v4 (v2025.03.14) |
| Jul 21, 2025 | 29.48% (0.29476) | 96.39th | v4 (v2025.03.14) |
| Jul 1, 2025 | 24.09% (0.24089) | 95.82th | v4 (v2025.03.14) |
| Mar 30, 2025 | 2.04% (0.02042) | 82.24th | v4 (v2025.03.14) |
| Mar 29, 2025 | 3.99% (0.03988) | 80.40th | v4 (v2025.03.14) |
| Mar 17, 2025 | 2.04% (0.02042) | 82.64th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.24% (0.00236) | 62.62th | v3 (v2023.03.01) |
| May 10, 2024 | 0.13% (0.00126) | 46.90th | v3 (v2023.03.01) |
| Apr 25, 2024 | 0.12% (0.00120) | 45.69th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.14% (0.00137) | 47.79th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.24% (0.00236) | 59.89th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.61% (0.04611) | 88.99th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.61% (0.04611) | 87.91th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.61% (0.04611) | 74.23th | v2 (v2022.01.01) |
References (6)
- http://rockwellautomation.custhelp.com/app/answers/detail/a_id/54102
- http://www.us-cert.gov/control_systems/pdf/ICSA-13-011-03.pdf US Government Resource
- https://rockwellautomation.custhelp.com/app/answers/detail/a_id/470154
- https://rockwellautomation.custhelp.com/app/answers/detail/aid/470155
- https://rockwellautomation.custhelp.com/app/answers/detail/aid/470156
- https://www.cisa.gov/news-events/ics-advisories/icsa-13-011-03
Change history (0)
No recorded changes yet.