CVE Vulnerabilities

CVE-2012-6440

Improper Authentication

Published: Jan 24, 2013 | Modified: Jun 30, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Web server password authentication mechanism used by the products is vulnerable to a MitM and Replay attack. Successful exploitation of this vulnerability will allow unauthorized access of the product’s Web server to view and alter product configuration and diagnostics information.

Rockwell Automation EtherNet/IP products; 1756-ENBT, 1756-EWEB, 1768-ENBT, and 1768-EWEB communication modules; CompactLogix L32E and L35E controllers; 1788-ENBT FLEXLogix adapter; 1794-AENTR FLEX I/O EtherNet/IP adapter; ControlLogix 18 and earlier; CompactLogix 18 and earlier; GuardLogix 18 and earlier; SoftLogix 18 and earlier; CompactLogix controllers 19 and earlier; SoftLogix controllers 19 and earlier; ControlLogix controllers 20 and earlier; GuardLogix controllers 20 and earlier; and MicroLogix 1100 and 1400

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Controllogix_controllersRockwellautomation*20 (including)
Guardlogix_controllersRockwellautomation*20 (including)
MicrologixRockwellautomation*1100 (including)
MicrologixRockwellautomation*1400 (including)
Softlogix_controllersRockwellautomation*19 (including)
1756-enbtRockwellautomation- (including)- (including)
1756-ewebRockwellautomation- (including)- (including)
1768-enbtRockwellautomation- (including)- (including)
1768-ewebRockwellautomation- (including)- (including)
1794-aentr_flex_i/o_ethernet/ip_adapterRockwellautomation- (including)- (including)
CompactlogixRockwellautomation*18 (including)
Compactlogix_controllersRockwellautomation*19 (including)
Compactlogix_l32e_controllerRockwellautomation- (including)- (including)
Compactlogix_l35e_controllerRockwellautomation- (including)- (including)
ControllogixRockwellautomation*18 (including)
Flexlogix_1788-enbt_adapterRockwellautomation- (including)- (including)
GuardlogixRockwellautomation*18 (including)
SoftlogixRockwellautomation*18 (including)

Potential Mitigations

References