Rockwell RSLogix 5000 Insufficiently Protected Credentials

Summary

CVECVE-2014-0755
StatePUBLISHED
Assignericscert
Source PriorityCVE Program / NVD first with legacy fallback
Published2014-02-05 05:15:29 UTC
Updated2026-04-29 01:13:23 UTC
DescriptionRockwell Automation RSLogix 5000 7 through 20.01, and 21.0, does not properly implement password protection for .ACD files (aka project files), which allows local users to obtain sensitive information or modify data via unspecified vectors.

Risk And Classification

Primary CVSS: v2.0 6.9 from [email protected]

AV:L/AC:M/Au:N/C:C/I:C/A:C

EPSS: 0.000040000 probability, percentile 0.001670000 (date 2026-05-04)

Problem Types: CWE-522 | CWE-255 | CWE-522 CWE-522


VersionSourceTypeScoreSeverityVector
2.0[email protected]Primary6.9AV:L/AC:M/Au:N/C:C/I:C/A:C
2.0[email protected]Secondary6.3AV:L/AC:M/Au:N/C:C/I:C/A:N
2.0CNACVSS6.3AV:L/AC:M/Au:N/C:C/I:C/A:N

CVSS v2.0 Breakdown

Access Vector
Local
Access Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete

AV:L/AC:M/Au:N/C:C/I:C/A:C

NVD Known Affected Configurations (CPE 2.3)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Rockwell Automation RSLogix 5000 Software affected V7 V20.01 custom Not specified
CNA Rockwell Automation RSLogix 5000 Software affected V7 V21.0 custom Not specified
CNA Rockwell Automation RSLogix 5000 Software unaffected V20.03 Not specified
CNA Rockwell Automation RSLogix 5000 Software unaffected V21.03 Not specified

References

ReferenceSourceLinkTags
IBM X-Force Exchange af854a3a-2127-422b-91ae-364da2661108 exchange.xforce.ibmcloud.com
www.cisa.gov/news-events/ics-advisories/icsa-14-021-01 [email protected] www.cisa.gov
rockwellautomation.custhelp.com/app/answers/detail/a_id/565204 [email protected] rockwellautomation.custhelp.com
Rockwell RSLogix 5000 Password Vulnerability | ICS-CERT af854a3a-2127-422b-91ae-364da2661108 ics-cert.us-cert.gov US Government Resource
osvdb.org/102858 af854a3a-2127-422b-91ae-364da2661108 osvdb.org
Rockwell Automation RSLogix 5000 CVE-2014-0755 Security Bypass Vulnerability af854a3a-2127-422b-91ae-364da2661108 www.securityfocus.com
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Vendor Comments And Credit

Discovery Credit

CNA: Stephen Dunlap (en)

Additional Advisory Data

Solutions

CNA: According to Rockwell Automation, new RSLogix 5000 versions, V20.03 and V21.03, have been released that address this vulnerability. These releases include mitigations that enhance password protection. Project files created in earlier affected RSLogix 5000 versions of software must be opened, resaved, and then downloaded to the appropriate controller to mitigate the risk associated with this discovered vulnerability. IMPORTANT: Files with protected content that have been opened and update using enhanced software will no longer be compatible with earlier versions of RSLogix 5000 software. For example, a V20.01 project file with protected content that has been opened and resaved using V20.03 software can only be opened with V20.03 and higher versions of software. Also, a V21.00 project file with protected content that has been opened and resaved using V21.03 software can only be opened with V21.03 and higher versions of software. For the procedure to update project files, please refer to Rockwell Automation Knowledgebase AID:565204 available here:  https://rockwellautomation.custhelp.com/app/answers/detail/a_id/565204  . In addition to using current RSLogix 5000 software, Rockwell Automation also recommends the following actions to all concerned customers: * Where possible, adopt a practice to track creation and distribution of protected ACD files, including duplicates and derivatives that contain protected content in the event that these files may need to be found or potentially disposed of in the future. * Where possible, securely archive protected ACD files or those that contain protected content in a manner that prevents unauthorized access. For instance, store protected ACD files in physical and logical locations where access can be controlled and the files are stored in a protected, potentially encrypted manner. * Where possible, securely transmit protected ACD files or those that contain protected content in a manner that prevents unauthorized access. For instance, email protected ACD files only to known recipients and encrypted the files such that only the target recipient can decrypt the content. * Where possible, restrict physical and network access to controllers containing protected content only to authorized parties in order to help prevent unauthorized uploading of protected material into an ACD file. For some customers, FactoryTalk Security software may be a suitable option to assist customers with applying a Role-based Access Control (RBAC) solution to their system. FactoryTalk Security was integrated into RSLogix 5000 Version 10.00. * Where possible, use a unique and complex password for each routine or Add-On Instruction desirable to protect, so as to reduce the risk that multiple files and protected content could be compromised, should a single password become learned. * Where possible, adopt a password management practice to periodically change passwords applied to routines and Add-On Instructions to help mitigate the risk that a learned password may remain usable for an extended period of time or indefinitely. Rockwell Automation encourages their customers to subscribe to Rockwell Automation’s Security Advisory Index (AID:54102)Rockwell Automation Knowledgebase AID:54102, https://rockwellautomation.custhelp.com/app/answers/detail/a_id/54102 , Web site last accessed February 04, 2014. for new and relevant information relating to this and other security-related matters. For more information and for assistance with assessing the state of security of your existing control system, including improving your system-level security when using Rockwell Automation and other vendor controls products, you can visit the Rockwell Automation Security Solutions Web site at http://www.rockwellautomation.com/solutions/security .

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report