Vulnerability Note VU#144233
Rockwell Automation Allen-Bradley MicroLogix PLC authentication and authorization vulnerabilities
Overview
Rockwell Automation Allen-Bradley MicroLogix programmable logic controllers (PLCs) do not adequately authenticate or authorize remote connections or commands. An attacker with network access can obtain the management password or issue commands that bypass the authentication mechanism.
Description
Rockwell Automation Allen-Bradley MicroLogix PLCs do not adequately authenticate or authorize remote connections or commands. Two vulnerable behaviors have been reported:
These vulnerabilities have been reported in the MicroLogix 1100 PLC. Other products in the MicroLogix series may also be affected. |
Impact
An attacker with network access to a controller could obtain the management password or issue commands that bypass the authentication mechanism. The attacker could disable the controller or change the configuration. |
Solution
Updated firmware is not available. Consider the workarounds listed below. Also, please see Technotes 65980 and 65982. |
Restrict access |
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Rockwell Automation | Affected | 04 Sep 2009 | 03 Jun 2010 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.securityfocus.com/archive/1/archive/1/508946/100/0/threaded
- http://www.ab.com/programmablecontrol/plc/micrologix/index.html
- http://www.rockwellautomation.com/rockwellsoftware/design/rslogix5/
- http://rockwellautomation.custhelp.com/app/answers/detail/a_id/65980/kw/65980/r_id/113025
- http://rockwellautomation.custhelp.com/app/answers/detail/a_id/65982/kw/65982/r_id/113025
- http://www.rockwellautomation.com/solutions/security
Credit
Thanks to Eyal Udassin of C4 Security for researching and reporting these vulnerabilities. Thanks also to Rockwell Automation for providing technical assistance and developing mitigation techniques.
This document was written by Art Manion.
Other Information
- CVE IDs: CVE-2009-3739
- Date Public: 18 Dec 2009
- Date First Published: 19 Jan 2010
- Date Last Updated: 03 Jun 2010
- Severity Metric: 8.91
- Document Revision: 23
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.