Rockwell Automation ControlLogix PLC Improper Access Control
Published Jan 24, 2013
8.5
HIGHCVSS 2.0
EPSS 23.18%
Description
When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that changes the product’s configuration and network parameters, a DoS condition can occur. This situation could cause loss of availability and a disruption of communication with other connected devices.
Rockwell Automation EtherNet/IP products; 1756-ENBT, 1756-EWEB, 1768-ENBT, and 1768-EWEB communication modules; CompactLogix L32E and L35E controllers; 1788-ENBT FLEXLogix adapter; 1794-AENTR FLEX I/O EtherNet/IP adapter; ControlLogix 18 and earlier; CompactLogix 18 and earlier; GuardLogix 18 and earlier; SoftLogix 18 and earlier; CompactLogix controllers 19 and earlier; SoftLogix controllers 19 and earlier; ControlLogix controllers 20 and earlier; GuardLogix controllers 20 and earlier; and MicroLogix 1100 and 1400
Affected products
- Vendor Rockwell Automation Product 1756-ENBT, 1756-EWEB, 1768-ENBT, 1768-EWEB communication modules Defaultunaffected
- Version AllStatusaffectedConstraints-
- Version
-
- Version AllStatusaffectedConstraints-
- Version
-
- Version AllStatusaffectedConstraints-
- Version
-
- Version AllStatusaffectedConstraints-
- Version
-
- Version 0StatusaffectedConstraints<=19
- Version
-
- Version 0StatusaffectedConstraints<=20
- Version
- Vendor Rockwell Automation Product ControlLogix, CompactLogix, GuardLogix, and SoftLogix Defaultunaffected
- Version 0StatusaffectedConstraints<=18
- Version
-
- Version 1100StatusaffectedConstraints-
- Version 1400StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Rockwell Automation | 1756-ENBT, 1756-EWEB, 1768-ENBT, 1768-EWEB communication modules | unaffected |
| |||||||||
| Rockwell Automation | 1788-ENBT FLEXLogix adapter | unaffected |
| |||||||||
| Rockwell Automation | 1794-AENTR FLEX I/O EtherNet/IP adapter | unaffected |
| |||||||||
| Rockwell Automation | CompactLogix L32E and L35E controllers | unaffected |
| |||||||||
| Rockwell Automation | CompactLogix and SoftLogix controllers | unaffected |
| |||||||||
| Rockwell Automation | ControlLogix and GuardLogix controllers | unaffected |
| |||||||||
| Rockwell Automation | ControlLogix, CompactLogix, GuardLogix, and SoftLogix | unaffected |
| |||||||||
| Rockwell Automation | MicroLogix | unaffected |
|
- ≤ 20
- ≤ 20
- ≤ 1100
- ≤ 1400
- ≤ 19
- n/a
- n/a
- n/a
- n/a
- n/a
- ≤ 18
- ≤ 19
- n/a
- n/a
- ≤ 18
- n/a
- ≤ 18
- ≤ 18
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
According to Rockwell, any of the above products that become affected by a vulnerability can be reset by rebooting or power cycling the affected product. After the reboot, the affected product may require some reconfiguration.
To mitigate the vulnerabilities, Rockwell has developed and released security patches on July 18, 2012, to address each of the issues. To download and install the patches please refer to Rockwell’s Advisories at:
https://rockwellautomation.custhelp.com/app/answers/detail/a_id/470154 https://rockwellautomation.custhelp.com/app/answers/detail/aid/470155 https://rockwellautomation.custhelp.com/app/answers/detail/aid/470156
For more information on security with Rockwell Automation products, please refer to Rockwell’s Security Advisory Index http://rockwellautomation.custhelp.com/app/answers/detail/a_id/54102 .
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:P/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 23.18% (0.23180) | 97.71th | v5 (v2026.06.15) |
| Aug 8, 2026 | 23.18% (0.23180) | 97.55th | v5 (v2026.06.15) |
| Jun 15, 2026 | 28.35% (0.28348) | 97.87th | v5 (v2026.06.15) |
| Jul 21, 2025 | 0.94% (0.00936) | 75.19th | v4 (v2025.03.14) |
| Jul 1, 2025 | 3.14% (0.03139) | 86.37th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.55% (0.01555) | 80.18th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.28% (0.00282) | 69.43th | v3 (v2023.03.01) |
| Apr 25, 2024 | 0.06% (0.00062) | 25.14th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.06% (0.00058) | 22.10th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.28% (0.00282) | 63.57th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.05% (0.01055) | 52.13th | v2 (v2022.01.01) |
| Sep 17, 2022 | 1.05% (0.01055) | 50.47th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.05% (0.01055) | 48.43th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.05% (0.01055) | 27.52th | v2 (v2022.01.01) |
References (5)
- http://rockwellautomation.custhelp.com/app/answers/detail/a_id/54102
- http://www.us-cert.gov/control_systems/pdf/ICSA-13-011-03.pdf x_refsource_MISCUS Government Resource
- https://rockwellautomation.custhelp.com/app/answers/detail/a_id/470154
- https://rockwellautomation.custhelp.com/app/answers/detail/aid/470155
- https://rockwellautomation.custhelp.com/app/answers/detail/aid/470156
Change history (0)
No recorded changes yet.