Security Flaw in Rockwell Automation EtherNet/IP Products and Controllers
CVE-2012-6440

4.8MEDIUM

What is CVE-2012-6440?

The web-server password authentication feature in various Rockwell Automation EtherNet/IP products and controllers is susceptible to man-in-the-middle attacks. Malicious actors can exploit this vulnerability to intercept and replay HTTP traffic, potentially compromising system integrity and exposing sensitive information. This issue affects multiple communication modules and controllers, emphasizing the need for users to implement security measures to safeguard against unauthorized access.

Affected Version(s)

1756-ENBT, 1756-EWEB, 1768-ENBT, 1768-EWEB communication modules All

1788-ENBT FLEXLogix adapter All

1794-AENTR FLEX I/O EtherNet/IP adapter All

References

EPSS Score

8% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.