Rockwell RSLogix 5000 Insufficiently Protected Credentials
Published Feb 5, 2014
6.9
MEDIUMCVSS 2.0
EPSS 0.56%
Description
Rockwell Automation RSLogix 5000 7 through 20.01, and 21.0, does not properly implement password protection for .ACD files (aka project files), which allows local users to obtain sensitive information or modify data via unspecified vectors.
Affected products
-
- Version V7StatusaffectedConstraints<=V20.01
- Version V7StatusaffectedConstraints<=V21.0
- Version V20.03StatusunaffectedConstraints-
- Version V21.03StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Rockwell Automation | RSLogix 5000 software | unaffected |
|
- 7.0
- 18.0
- 20.01
- 21.0
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
According to Rockwell Automation, new RSLogix 5000 versions, V20.03 and V21.03, have been released that address this vulnerability. These releases include mitigations that enhance password protection.
Project files created in earlier affected RSLogix 5000 versions of software must be opened, resaved, and then downloaded to the appropriate controller to mitigate the risk associated with this discovered vulnerability.
IMPORTANT: Files with protected content that have been opened and update using enhanced software will no longer be compatible with earlier versions of RSLogix 5000 software. For example, a V20.01 project file with protected content that has been opened and resaved using V20.03 software can only be opened with V20.03 and higher versions of software. Also, a V21.00 project file with protected content that has been opened and resaved using V21.03 software can only be opened with V21.03 and higher versions of software.
For the procedure to update project files, please refer to Rockwell Automation Knowledgebase AID:565204 available here: https://rockwellautomation.custhelp.com/app/answers/detail/a_id/565204 .
In addition to using current RSLogix 5000 software, Rockwell Automation also recommends the following actions to all concerned customers:
* Where possible, adopt a practice to track creation and distribution of protected ACD files, including duplicates and derivatives that contain protected content in the event that these files may need to be found or potentially disposed of in the future.
* Where possible, securely archive protected ACD files or those that contain protected content in a manner that prevents unauthorized access. For instance, store protected ACD files in physical and logical locations where access can be controlled and the files are stored in a protected, potentially encrypted manner.
* Where possible, securely transmit protected ACD files or those that contain protected content in a manner that prevents unauthorized access. For instance, email protected ACD files only to known recipients and encrypted the files such that only the target recipient can decrypt the content.
* Where possible, restrict physical and network access to controllers containing protected content only to authorized parties in order to help prevent unauthorized uploading of protected material into an ACD file. For some customers, FactoryTalk Security software may be a suitable option to assist customers with applying a Role-based Access Control (RBAC) solution to their system. FactoryTalk Security was integrated into RSLogix 5000 Version 10.00.
* Where possible, use a unique and complex password for each routine or Add-On Instruction desirable to protect, so as to reduce the risk that multiple files and protected content could be compromised, should a single password become learned.
* Where possible, adopt a password management practice to periodically change passwords applied to routines and Add-On Instructions to help mitigate the risk that a learned password may remain usable for an extended period of time or indefinitely.
Rockwell Automation encourages their customers to subscribe to Rockwell Automation’s Security Advisory Index (AID:54102)Rockwell Automation Knowledgebase AID:54102, https://rockwellautomation.custhelp.com/app/answers/detail/a_id/54102 , Web site last accessed February 04, 2014. for new and relevant information relating to this and other security-related matters.
For more information and for assistance with assessing the state of security of your existing control system, including improving your system-level security when using Rockwell Automation and other vendor controls products, you can visit the Rockwell Automation Security Solutions Web site at http://www.rockwellautomation.com/solutions/security .
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:M/Au:N/C:C/I:C/A:C
1 other source (CVE.org) ▾
AV:L/AC:M/Au:N/C:C/I:C/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.56% (0.00563) | 44.79th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.56% (0.00563) | 42.17th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.00% (0.00003) | 0.11th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.06% (0.00061) | 28.04th | v3 (v2023.03.01) |
| Jun 7, 2024 | 0.06% (0.00061) | 25.87th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.06% (0.00061) | 23.86th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.95% (0.00950) | 32.28th | v2 (v2022.01.01) |
| Sep 10, 2022 | 0.95% (0.00950) | 30.63th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.95% (0.00950) | 28.61th | v2 (v2022.01.01) |
| Feb 4, 2022 | 0.95% (0.00950) | 13.46th | v2 (v2022.01.01) |
References (6)
- http://ics-cert.us-cert.gov/advisories/ICSA-14-021-01 US Government Resource
- http://osvdb.org/102858 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/bid/65337 vdb-entryx_refsource_BID
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90981 vdb-entryx_refsource_XF
- https://rockwellautomation.custhelp.com/app/answers/detail/a_id/565204
- https://www.cisa.gov/news-events/ics-advisories/icsa-14-021-01
| Link | Providers | Tags |
|---|---|---|
| http://ics-cert.us-cert.gov/advisories/ICSA-14-021-01 | US Government Resource | |
| http://osvdb.org/102858 | vdb-entryx_refsource_OSVDB | |
| http://www.securityfocus.com/bid/65337 | vdb-entryx_refsource_BID | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/90981 | vdb-entryx_refsource_XF | |
| https://rockwellautomation.custhelp.com/app/answers/detail/a_id/565204 | ||
| https://www.cisa.gov/news-events/ics-advisories/icsa-14-021-01 |
Change history (0)
No recorded changes yet.