Rockwell RSLogix 5000 Insufficiently Protected Credentials
Summary
| CVE | CVE-2014-0755 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-02-05 05:15:29 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Rockwell Automation RSLogix 5000 7 through 20.01, and 21.0, does not properly implement password protection for .ACD files (aka project files), which allows local users to obtain sensitive information or modify data via unspecified vectors. |
Risk And Classification
Primary CVSS: v2.0 6.9 from [email protected]
AV:L/AC:M/Au:N/C:C/I:C/A:C
EPSS: 0.000040000 probability, percentile 0.001670000 (date 2026-05-04)
Problem Types: CWE-522 | CWE-255 | CWE-522 CWE-522
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 2.0 | [email protected] | Primary | 6.9 | AV:L/AC:M/Au:N/C:C/I:C/A:C | |
| 2.0 | [email protected] | Secondary | 6.3 | AV:L/AC:M/Au:N/C:C/I:C/A:N | |
| 2.0 | CNA | CVSS | 6.3 | AV:L/AC:M/Au:N/C:C/I:C/A:N |
CVSS v2.0 Breakdown
AV:L/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Rockwellautomation | Logix 5000 Controller | - | All | All | All |
| Application | Rockwellautomation | Rslogix 5000 Design And Configuration Software | 18.0 | All | All | All |
| Application | Rockwellautomation | Rslogix 5000 Design And Configuration Software | 20.01 | All | All | All |
| Application | Rockwellautomation | Rslogix 5000 Design And Configuration Software | 21.0 | All | All | All |
| Application | Rockwellautomation | Rslogix 5000 Design And Configuration Software | 7.0 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Rockwell Automation | RSLogix 5000 Software | affected V7 V20.01 custom | Not specified |
| CNA | Rockwell Automation | RSLogix 5000 Software | affected V7 V21.0 custom | Not specified |
| CNA | Rockwell Automation | RSLogix 5000 Software | unaffected V20.03 | Not specified |
| CNA | Rockwell Automation | RSLogix 5000 Software | unaffected V21.03 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| www.cisa.gov/news-events/ics-advisories/icsa-14-021-01 | [email protected] | www.cisa.gov | |
| rockwellautomation.custhelp.com/app/answers/detail/a_id/565204 | [email protected] | rockwellautomation.custhelp.com | |
| Rockwell RSLogix 5000 Password Vulnerability | ICS-CERT | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | US Government Resource |
| osvdb.org/102858 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Rockwell Automation RSLogix 5000 CVE-2014-0755 Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Stephen Dunlap (en)
Additional Advisory Data
Solutions
CNA: According to Rockwell Automation, new RSLogix 5000 versions, V20.03 and V21.03, have been released that address this vulnerability. These releases include mitigations that enhance password protection. Project files created in earlier affected RSLogix 5000 versions of software must be opened, resaved, and then downloaded to the appropriate controller to mitigate the risk associated with this discovered vulnerability. IMPORTANT: Files with protected content that have been opened and update using enhanced software will no longer be compatible with earlier versions of RSLogix 5000 software. For example, a V20.01 project file with protected content that has been opened and resaved using V20.03 software can only be opened with V20.03 and higher versions of software. Also, a V21.00 project file with protected content that has been opened and resaved using V21.03 software can only be opened with V21.03 and higher versions of software. For the procedure to update project files, please refer to Rockwell Automation Knowledgebase AID:565204 available here: https://rockwellautomation.custhelp.com/app/answers/detail/a_id/565204 . In addition to using current RSLogix 5000 software, Rockwell Automation also recommends the following actions to all concerned customers: * Where possible, adopt a practice to track creation and distribution of protected ACD files, including duplicates and derivatives that contain protected content in the event that these files may need to be found or potentially disposed of in the future. * Where possible, securely archive protected ACD files or those that contain protected content in a manner that prevents unauthorized access. For instance, store protected ACD files in physical and logical locations where access can be controlled and the files are stored in a protected, potentially encrypted manner. * Where possible, securely transmit protected ACD files or those that contain protected content in a manner that prevents unauthorized access. For instance, email protected ACD files only to known recipients and encrypted the files such that only the target recipient can decrypt the content. * Where possible, restrict physical and network access to controllers containing protected content only to authorized parties in order to help prevent unauthorized uploading of protected material into an ACD file. For some customers, FactoryTalk Security software may be a suitable option to assist customers with applying a Role-based Access Control (RBAC) solution to their system. FactoryTalk Security was integrated into RSLogix 5000 Version 10.00. * Where possible, use a unique and complex password for each routine or Add-On Instruction desirable to protect, so as to reduce the risk that multiple files and protected content could be compromised, should a single password become learned. * Where possible, adopt a password management practice to periodically change passwords applied to routines and Add-On Instructions to help mitigate the risk that a learned password may remain usable for an extended period of time or indefinitely. Rockwell Automation encourages their customers to subscribe to Rockwell Automation’s Security Advisory Index (AID:54102)Rockwell Automation Knowledgebase AID:54102, https://rockwellautomation.custhelp.com/app/answers/detail/a_id/54102 , Web site last accessed February 04, 2014. for new and relevant information relating to this and other security-related matters. For more information and for assistance with assessing the state of security of your existing control system, including improving your system-level security when using Rockwell Automation and other vendor controls products, you can visit the Rockwell Automation Security Solutions Web site at http://www.rockwellautomation.com/solutions/security .