Rockwell Automation ControlLogix PLC Improper Authentication

Summary

CVECVE-2012-6437
StatePUBLISHED
Assignericscert
Source PriorityCVE Program / NVD first with legacy fallback
Published2013-01-24 21:55:01 UTC
Updated2026-04-29 01:13:23 UTC
DescriptionThe device does not properly authenticate users and the potential exists for a remote user to upload a new firmware image to the Ethernet card, whether it is a corrupt or legitimate firmware image. Successful exploitation of this vulnerability could cause loss of availability, integrity, and confidentiality and a disruption in communications with other connected devices. Rockwell Automation EtherNet/IP products; 1756-ENBT, 1756-EWEB, 1768-ENBT, and 1768-EWEB communication modules; CompactLogix L32E and L35E controllers; 1788-ENBT FLEXLogix adapter; 1794-AENTR FLEX I/O EtherNet/IP adapter; ControlLogix 18 and earlier; CompactLogix 18 and earlier; GuardLogix 18 and earlier; SoftLogix 18 and earlier; CompactLogix controllers 19 and earlier; SoftLogix controllers 19 and earlier; ControlLogix controllers 20 and earlier; GuardLogix controllers 20 and earlier; and MicroLogix 1100 and 1400

Risk And Classification

Primary CVSS: v2.0 10 from [email protected]

AV:N/AC:L/Au:N/C:C/I:C/A:C

Problem Types: CWE-287 | CWE-287 CWE-287


VersionSourceTypeScoreSeverityVector
2.0[email protected]Primary10AV:N/AC:L/Au:N/C:C/I:C/A:C
2.0[email protected]Secondary10AV:N/AC:L/Au:N/C:C/I:C/A:C
2.0CNACVSS10AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS v2.0 Breakdown

Access Vector
Network
Access Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete

AV:N/AC:L/Au:N/C:C/I:C/A:C

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Hardware Rockwellautomation 1756-enbt - All All All
Hardware Rockwellautomation 1756-eweb - All All All
Hardware Rockwellautomation 1768-enbt - All All All
Hardware Rockwellautomation 1768-eweb - All All All
Hardware Rockwellautomation 1794-aentr Flex I/o Ethernet/ip Adapter - All All All
Hardware Rockwellautomation Compactlogix All All All All
Hardware Rockwellautomation Compactlogix Controllers All All All All
Hardware Rockwellautomation Compactlogix L32e Controller - All All All
Hardware Rockwellautomation Compactlogix L35e Controller - All All All
Hardware Rockwellautomation Controllogix All All All All
Application Rockwellautomation Controllogix Controllers All All All All
Hardware Rockwellautomation Flexlogix 1788-enbt Adapter - All All All
Hardware Rockwellautomation Guardlogix All All All All
Application Rockwellautomation Guardlogix Controllers All All All All
Application Rockwellautomation Micrologix All All All All
Application Rockwellautomation Micrologix All All All All
Hardware Rockwellautomation Softlogix All All All All
Application Rockwellautomation Softlogix Controllers All All All All

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Rockwell Automation 1756-ENBT 1756-EWEB 1768-ENBT 1768-EWEB Communication Modules affected All Not specified
CNA Rockwell Automation CompactLogix L32E And L35E Controllers affected All Not specified
CNA Rockwell Automation 1788-ENBT FLEXLogix Adapter affected All Not specified
CNA Rockwell Automation 1794-AENTR FLEX I/O EtherNet/IP Adapter affected All Not specified
CNA Rockwell Automation ControlLogix CompactLogix GuardLogix And SoftLogix affected 18 custom Not specified
CNA Rockwell Automation CompactLogix And SoftLogix Controllers affected 19 custom Not specified
CNA Rockwell Automation ControlLogix And GuardLogix Controllers affected 20 custom Not specified
CNA Rockwell Automation MicroLogix affected 1100 Not specified
CNA Rockwell Automation MicroLogix affected 1400 Not specified

References

ReferenceSourceLinkTags
rockwellautomation.custhelp.com/app/answers/detail/aid/470155 [email protected] rockwellautomation.custhelp.com
rockwellautomation.custhelp.com/app/answers/detail/aid/470156 [email protected] rockwellautomation.custhelp.com
rockwellautomation.custhelp.com/app/answers/detail/a_id/54102 [email protected] rockwellautomation.custhelp.com
rockwellautomation.custhelp.com/app/answers/detail/a_id/470154 [email protected] rockwellautomation.custhelp.com
404 - File Not Found | CISA af854a3a-2127-422b-91ae-364da2661108 www.us-cert.gov US Government Resource
www.cisa.gov/news-events/ics-advisories/icsa-13-011-03 [email protected] www.cisa.gov
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Vendor Comments And Credit

Discovery Credit

CNA: Rubén Santamarta of IOActive identified vulnerabilities in Rockwell Automation’s ControlLogix PLC and released proof-of-concept (exploit) code at the Digital Bond S4 Conference on January 19, 2012. (en)

Additional Advisory Data

Solutions

CNA: According to Rockwell, any of the above products that become affected by a vulnerability can be reset by rebooting or power cycling the affected product. After the reboot, the affected product may require some reconfiguration. To mitigate the vulnerabilities, Rockwell has developed and released security patches on July 18, 2012, to address each of the issues. To download and install the patches please refer to Rockwell’s Advisories at: https://rockwellautomation.custhelp.com/app/answers/detail/a_id/470154 https://rockwellautomation.custhelp.com/app/answers/detail/aid/470155 https://rockwellautomation.custhelp.com/app/answers/detail/aid/470156 For more information on security with Rockwell Automation products, please refer to Rockwell’s Security Advisory Index http://rockwellautomation.custhelp.com/app/answers/detail/a_id/54102 .

Workarounds

CNA: Rockwell recommends updating to the newest firmware patches to fix the vulnerabilities, but if not able to do so right away, then Rockwell advises immediately employing the following mitigations for each of the affected products. To mitigate the vulnerability with the Web server password authentication mechanism: * Upgrade the MicroLogix 1400 firmware to FRN 12 or higher. * Because of limitations in the MicroLogix 1100 platform, none of the firmware updates will be able to fix this issue, so users should use the following techniques to help reduce the likelihood of compromise. * Where possible, disable the Web server and change all default Administrator and Guest passwords. * If Web server functionality is needed, then Rockwell recommends upgrading the product’s firmware to the most current version to have the newest enhanced protections available such as: * When a controller receives two consecutive invalid authentication requests from an HTTP client, the controller resets the Authentication Counter after 60 minutes. * When a controller receives 10 invalid authentication requests from any HTTP client, it will not accept any valid or invalid authentication packets until a 24-hour HTTP Server Lock Timer timeout. * If Web server functionality is needed, Rockwell also recommends configuring user accounts to have READ only access to the product so those accounts cannot be used to make configuration change In addition to the above, Rockwell recommends concerned customers remain vigilant and continue to follow security strategies that help reduce risk and enhance overall control system security. Where possible, they suggest you apply multiple recommendations and complement this list with your own best-practices: * Employ layered security and defense-in-depth methods in system design to restrict and control access to individual products and control networks. Refer to http://www.ab.com/networks/architectures.html for comprehensive information about implementing validated architectures designed to deliver these measures. * Restrict physical and electronic access to automation products, networks, and systems to only those individuals authorized to be in contact with control system equipment. * Employ firewalls with ingress/egress filtering, intrusion detection/prevention systems, and validate all configurations. Evaluate firewall configurations to ensure other appropriate inbound and outbound traffic is blocked. * Use up-to-date end-point protection software (e.g., antivirus/antimalware software) on all PC-based assets. * Make sure that software and control system device firmware is patched to current releases. * Periodically change passwords in control system components and infrastructure devices. * Where applicable, set the controller key-switch/mode-switch to RUN mode. For more information on security with Rockwell Automation products, please refer to Rockwell’s Security Advisory Index http://rockwellautomation.custhelp.com/app/answers/detail/a_id/54102 .

© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report