Rockwell Automation Multiple Product MitM replay authentication suffers from bypass vulnerability.
Credit:
The information has been provided by Rub n Santamarta .
The original article can be found at: http://www.us-cert.gov/control_systems/pdf/ICSA-13-011-03.pdf
Vulnerable Systems:
* Rockwell Automation ControlLogix 18 and prior
* Rockwell Automation MicroLogix 1100 and prior
* Rockwell Automation 1756-ENBT
* Rockwell Automation 1768-ENBT
* Rockwell Automation 1768-EWEB
* Rockwell Automation 1788-ENBT FLEX
* Rockwell Automation 1794-AENTR FLEX
* Rockwell Automation CompactLogix 18 and prior
* Rockwell Automation GuardLogix 18 and prior
Multiple Rockwell Automation products contain a flaw that is due to the program failing to properly restrict session replaying. This may allow a remote attacker to bypass authentication via a man-in-the-middle attack.
CVE Information:
2012-6440
Disclosure Timeline:
Vendor Solution Date :2012-07-18
Disclosure Date :2013-01-11
Please enable JavaScript to view the comments powered by Disqus.
blog comments powered by