7.8
CVSSv2

CVE-2018-17924

Published: 07/12/2018 Updated: 02/05/2022
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 8.6 | Impact Score: 4 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Rockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unauthenticated, remote threat actor could send a CIP connection request to an affected device, and upon successful connection, send a new IP configuration to the affected device even if the controller in the system is set to Hard RUN mode. When the affected device accepts this new IP configuration, a loss of communication occurs between the device and the rest of the system as the system traffic is still attempting to communicate with the device via the overwritten IP address.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rockwellautomation micrologix_1400_firmware -

rockwellautomation 1756-enbt_firmware -

rockwellautomation 1756-eweb_series_a_firmware -

rockwellautomation 1756-eweb_series_b_firmware -

rockwellautomation 1756-en2f_series_a_firmware -

rockwellautomation 1756-en2f_series_b_firmware -

rockwellautomation 1756-en2f_series_c_firmware

rockwellautomation 1756-en2t_series_a_firmware -

rockwellautomation 1756-en2t_series_b_firmware -

rockwellautomation 1756-en2t_series_c_firmware -

rockwellautomation 1756-en2t_series_d_firmware

rockwellautomation 1756-en2tr_series_a_firmware -

rockwellautomation 1756-en2tr_series_b_firmware -

rockwellautomation 1756-en2tr_series_c_firmware

rockwellautomation 1756-en3tr_series_a_firmware -

rockwellautomation 1756-en3tr_series_b_firmware

Github Repositories

My team research about CVE-2018-17924 of Rockwell Automation Micrologix 1400

CVE-2018-17924 My team research about CVE-2018-17924 of Rockwell Automation Micrologix 1400 This research occured when I participated in OPSWAT fellowship program in 10/2023 Blog wwwopswatcom/blog/strengthening-ot-security-against-cve-2018-17924-with-metadefender-ot-solutions