Information disclosure in Allen-Bradley MicroLogix 1100 and Allen-Bradley MicroLogix 1400 - CVE-2017-7899

 

Information disclosure in Allen-Bradley MicroLogix 1100 and Allen-Bradley MicroLogix 1400 - CVE-2017-7899

Published: May 24, 2017


Vulnerability identifier: #VU6696
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7899
CWE-ID: CWE-598
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to obtain potentially sensitive information on the target system.

The vulnerability exists due to an error when sending credentials to the web server using the HTTP GET method, which may result in the credentials being logged.

Successful exploitation of the vulnerability may result in unauthorized retrieval of the user credentials.


Affected software

Allen-Bradley MicroLogix 1100
Allen-Bradley MicroLogix 1400

How to mitigate CVE-2017-7899

Update to version 21.00


External References

Related Security Bulletins