CVE-2012-4690
Rockwell Automation Allen-Bradley MicroLogix controller 1100, 1200, 1400, and 1500; SLC 500 controller platform; and PLC-5 controller platform, when Static status is not enabled, allow remote attackers to cause a denial of service via messages that…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.05%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Rockwell Automation Allen-Bradley MicroLogix controller 1100, 1200, 1400, and 1500; SLC 500 controller platform; and PLC-5 controller platform, when Static status is not enabled, allow remote attackers to cause a denial of service via messages that trigger modification of status bits.
- CVSS 2.0
- 7.1 HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
- EPSS
- 4.05% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-16
- Affected
- rockwellautomation/ab micrologix controller · rockwellautomation/plc-5 controller · rockwellautomation/slc 500 controller
- Source
- ics-cert@hq.dhs.gov
References
- http://ics-cert.us-cert.gov/advisories/ICSA-12-342-01A
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-342-01.pdfUS Government Resource
- https://rockwellautomation.custhelp.com/app/answers/detail/a_id/511407
- http://ics-cert.us-cert.gov/advisories/ICSA-12-342-01A
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-342-01.pdfUS Government Resource
- https://rockwellautomation.custhelp.com/app/answers/detail/a_id/511407
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.