CVE-2020-6990
An attacker could identify cryptographic keys and use it for further cryptographic attacks that could ultimately lead to a remote attacker gaining unauthorized access to the controller.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.37%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic key utilized to help protect the account password is hard coded into the RSLogix 500 binary file. An attacker could identify cryptographic keys and use it for further cryptographic attacks that could ultimately lead to a remote attacker gaining unauthorized access to the controller.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.37% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-321, CWE-798
- Affected
- rockwellautomation/micrologix 1400 a firmware · rockwellautomation/micrologix 1400 b firmware · rockwellautomation/micrologix 1100 firmware · rockwellautomation/rslogix 500
- Source
- ics-cert@hq.dhs.gov
References
- https://www.us-cert.gov/ics/advisories/icsa-20-070-06Third Party Advisory, US Government Resource
- https://www.us-cert.gov/ics/advisories/icsa-20-070-06Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.