CVE-2020-6990
Summary
| CVE | CVE-2020-6990 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-03-16 16:15:00 UTC |
| Updated | 2020-03-20 15:09:00 UTC |
| Description | Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic key utilized to help protect the account password is hard coded into the RSLogix 500 binary file. An attacker could identify cryptographic keys and use it for further cryptographic attacks that could ultimately lead to a remote attacker gaining unauthorized access to the controller. |
Risk And Classification
Problem Types: CWE-798
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Rockwellautomation | Micrologix 1100 | - | All | All | All |
| Hardware | Rockwellautomation | Micrologix 1100 | - | All | All | All |
| Operating System | Rockwellautomation | Micrologix 1100 Firmware | All | All | All | All |
| Operating System | Rockwellautomation | Micrologix 1100 Firmware | All | All | All | All |
| Hardware | Rockwellautomation | Micrologix 1400 | - | All | All | All |
| Hardware | Rockwellautomation | Micrologix 1400 | - | All | All | All |
| Operating System | Rockwellautomation | Micrologix 1400 A Firmware | All | All | All | All |
| Operating System | Rockwellautomation | Micrologix 1400 A Firmware | All | All | All | All |
| Operating System | Rockwellautomation | Micrologix 1400 B Firmware | All | All | All | All |
| Application | Rockwellautomation | Rslogix 500 | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Rockwell Automation MicroLogix Controllers and RSLogix 500 Software | CISA | MISC | www.us-cert.gov | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.