Rockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unauthenticated, remote threat actor could send a CIP connection request to an affected device, and upon successful connection, send a new IP configuration to the affected device even if the controller in the system is set to Hard RUN mode
Published Dec 7, 2018
8.6
HIGHCVSS 3.1
EPSS 4.33%
Description
Rockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unauthenticated, remote threat actor could send a CIP connection request to an affected device, and upon successful connection, send a new IP configuration to the affected device even if the controller in the system is set to Hard RUN mode. When the affected device accepts this new IP configuration, a loss of communication occurs between the device and the rest of the system as the system traffic is still attempting to communicate with the device via the overwritten IP address.
Affected products
- Vendor n/a Product Rockwell Automation Defaultn/a
- Version MicroLogix 1400 Controllers Series A, all versions, Series B, v21.003 and earlier,Series C, v21.003 and earlier, 1756 ControlLogix EtherNet/IP Communications Modules 1756-ENBT, all versions, 1756-EWEB Series A, all versions Series B, all versions, 1756-EN2F Series A, all versions, Series B, all versions, Series C, v10.10 and earlier, 1756-EN2T, Series A, all versions, Series B, all versions, Series C, all versions, Series D, v10.10 and earlier, 1756-EN2TR, Series A, all versions, Series B, all versions, Series C, v10.10 and earlier, 1756-EN3TR, Series A, all versions, Series B, v10.10 and earlier.StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Rockwell Automation | n/a |
|
Configuration 1
Running on/with
- n/a
Configuration 2
- n/a
Running on/with
- n/a
Configuration 3
Running on/with
- n/a
Configuration 4
Running on/with
- n/a
Configuration 5
Running on/with
- n/a
Configuration 6
Running on/with
- n/a
Configuration 7
- ≤ 10.10
Running on/with
- n/a
Configuration 8
Running on/with
- n/a
Configuration 9
Running on/with
- n/a
Configuration 10
Running on/with
- n/a
Configuration 11
- ≤ 10.10
Running on/with
- n/a
Configuration 12
Running on/with
- n/a
Configuration 13
Running on/with
- n/a
Configuration 14
- ≤ 10.10
Running on/with
- n/a
Configuration 15
Running on/with
- n/a
Configuration 16
- ≤ 10.10
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- http://www.securityfocus.com/bid/106132 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-9665 Advisory
- https://ics-cert.us-cert.gov/advisories/ICSA-18-310-02 x_refsource_MISCMitigationThird Party AdvisoryUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/106132 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-9665 | Advisory | |
| https://ics-cert.us-cert.gov/advisories/ICSA-18-310-02 | x_refsource_MISCMitigationThird Party AdvisoryUS Government Resource |
Change history (0)
No recorded changes yet.