CVE-2020-6980
Summary
| CVE | CVE-2020-6980 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-03-16 16:15:00 UTC |
| Updated | 2020-03-20 14:28:00 UTC |
| Description | Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, If Simple Mail Transfer Protocol (SMTP) account data is saved in RSLogix 500, a local attacker with access to a victim’s project may be able to gather SMTP server authentication data as it is written to the project file in cleartext. |
Risk And Classification
Problem Types: CWE-312
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Rockwellautomation | Micrologix 1100 | - | All | All | All |
| Hardware | Rockwellautomation | Micrologix 1100 | - | All | All | All |
| Operating System | Rockwellautomation | Micrologix 1100 Firmware | All | All | All | All |
| Operating System | Rockwellautomation | Micrologix 1100 Firmware | All | All | All | All |
| Hardware | Rockwellautomation | Micrologix 1400 | - | All | All | All |
| Hardware | Rockwellautomation | Micrologix 1400 | - | All | All | All |
| Operating System | Rockwellautomation | Micrologix 1400 A Firmware | All | All | All | All |
| Operating System | Rockwellautomation | Micrologix 1400 A Firmware | All | All | All | All |
| Operating System | Rockwellautomation | Micrologix 1400 B Firmware | All | All | All | All |
| Application | Rockwellautomation | Rslogix 500 | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Rockwell Automation MicroLogix Controllers and RSLogix 500 Software | CISA | MISC | www.us-cert.gov | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.