Information disclosure in Allen-Bradley MicroLogix 1100 and Allen-Bradley MicroLogix 1400 - CVE-2017-7899
Published: May 24, 2017
Vulnerability identifier: #VU6696
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7899
CWE-ID: CWE-598
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to obtain potentially sensitive information on the target system.
The vulnerability exists due to an error when sending credentials to the web server using the HTTP GET method, which may result in the credentials being logged.
Successful exploitation of the vulnerability may result in unauthorized retrieval of the user credentials.
Affected software
Allen-Bradley MicroLogix 1100
Allen-Bradley MicroLogix 1400
Allen-Bradley MicroLogix 1400
How to mitigate CVE-2017-7899
Update to version 21.00