CVE-2020-6988 Information
Feb 14, 2021
cve
Description
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior Series A all versions MicroLogix 1100 Controller all versions RSLogix 500 Software v12.001 and prior A remote unauthenticated attacker can send a request from the RSLogix 500 software to the victim’s MicroLogix controller. The controller will then respond to the client with used password values to authenticate the user on the client-side. This method of authentication may allow an attacker to bypass authentication altogether disclose sensitive information or leak credentials.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference
https://www.us-cert.gov/ics/advisories/icsa-20-070-06
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
7.5
Share on: