Vulnerability CVE-2010-5305


Published: 2019-03-26

Description:
The potential exists for exposure of the product's password used to restrict unauthorized access to Rockwell PLC5/SLC5/0x/RSLogix 1785-Lx and 1747-L5x controllers. The potential exists for an unauthorized programming and configuration client to gain access to the product and allow changes to the product?s configuration or program. When applicable, upgrade product firmware to a version that includes enhanced security functionality compatible with Rockwell Automation's FactoryTalk Security services.

Type:

CWE-284

(Improper Access Control)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Rockwellautomation -> Rslogix 
Rockwellautomation -> Plc5 1785-lx firmware 
Rockwellautomation -> Slc5/01 1747-l5x firmware 

 References:
https://ics-cert.us-cert.gov/advisories/ICSA-10-070-02

Copyright 2020, cxsecurity.com

 

Back to Top