CVE-2018-17924
—CVSS 3.1
8.6 high
EPSS
4%p91
Published
()
Modified
Description
Rockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unauthenticated, remote threat actor could send a CIP connection request to an affected device, and upon successful connection, send a new IP configuration to the affected device even if the controller in the system is set to Hard RUN mode. When the affected device accepts this new IP configuration, a loss of communication occurs between the device and the rest of the system as the system traffic is still attempting to communicate with the device via the overwritten IP address.
- Vendors
- rockwellautomation
- Products
- micrologix 1400 firmware, 1756-enbt firmware, 1756-eweb series a firmware, 1756-eweb series b firmware, 1756-en2f series a firmware, 1756-en2f series b firmware, 1756-en2f series c firmware, 1756-en2t series a firmware, 1756-en2t series b firmware, 1756-en2t series c firmware, 1756-en2t series d firmware, 1756-en2tr series a firmware
- Weakness
- CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.