Release date:
Updated on: 2013-01-19
Affected Systems:
Rockwell Automation Micrologix 1400
Rockwell Automation Micrologix 1100
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57317
CVE (CAN) ID: CVE-2012-6437
Rockwell Automation ControlLogix provides industrial Automation control and information products.
Rockwell Automation ControlLogix has a security vulnerability. Attackers can exploit this vulnerability to bypass the authentication process and upload a new firmware image to the ethernet card.
<* Source: Rub & #195; & #169; n Santamarta
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Rockwell Automation
-------------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.rockwellautomation.com/