Back

HIGH

Rockwell Automation Micrologix 1400 Improper Input Validation

Published Oct 3, 2014

Description

The DNP3 feature on Rockwell Automation Allen-Bradley MicroLogix 1400 1766-Lxxxxx A FRN controllers 7 and earlier and 1400 1766-Lxxxxx B FRN controllers before 15.001 allows remote attackers to cause a denial of service (process disruption) via malformed packets over (1) an Ethernet network or (2) a serial line.

Affected products

Remediation

Vendor solution

Rockwell Automation has released a new version of MicroLogix 1400 Series B firmware to address the vulnerability and reduce associated risk to successful exploitation. Subsequent versions of MicroLogix 1400 Series B firmware and newer will incorporate these same enhancements.

Rockwell Automation recommends the following immediate mitigation strategies (when possible, multiple strategies should be employed simultaneously):

* Upgrade all MicroLogix 1400 Series B controllers to Series B FRN 15.001 or higher. Current firmware for the MicroLogix 1400 Series B platform can be obtained at the following web address:

http://www.rockwellautomation.com/rockwellautomation/support/pcdc.page

Please refer to Rockwell Automation’s product disclosure (AID 620295) for more information on this topic available at:

https://rockwellautomation.custhelp.com/app/answers/detail/a_id/620295

Metrics

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Oct 3, 2014
Updated Nov 4, 2025
Reserved Aug 22, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a