Security Flaw in Rockwell Automation EtherNet/IP Products and Controllers
CVE-2012-6440
4.8MEDIUM
Key Information:
- Vendor
Rockwell Automation
- Status
- Vendor
- CVE Published:
- 24 January 2013
What is CVE-2012-6440?
The web-server password authentication feature in various Rockwell Automation EtherNet/IP products and controllers is susceptible to man-in-the-middle attacks. Malicious actors can exploit this vulnerability to intercept and replay HTTP traffic, potentially compromising system integrity and exposing sensitive information. This issue affects multiple communication modules and controllers, emphasizing the need for users to implement security measures to safeguard against unauthorized access.
Affected Version(s)
1756-ENBT, 1756-EWEB, 1768-ENBT, 1768-EWEB communication modules All
1788-ENBT FLEXLogix adapter All
1794-AENTR FLEX I/O EtherNet/IP adapter All
References
EPSS Score
8% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability Reserved
Vulnerability published