CVE Feed

    Dashboard / CVE / CVE-2017-12093

    CVE-2017-12093

    An exploitable insufficient resource pool vulnerability exists in the session communication functionality of Allen Bradley Micrologix 1400 Series B Firmware 21.2 and before. A specially crafted stream of packets can cause a flood of the session resource pool resulting in legitimate connections to the PLC being disconnected. An attacker can send unauthenticated packets to trigger this vulnerability.

    Published:Apr 5, 2018
    Last Modified:Nov 21, 2024
    EPS:Apr 5, 2018
    EPSS Score:0.03237
    CVSS Score:5.3

    Affected Products

    Vendor
    Rockwellautomation
    Product
    Micrologix 1400
    Vendor
    Rockwellautomation
    Product
    Micrologix 1400 B Firmware

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High