← Back to home
ICSA-16-224-01  ·  Published 2025-06-09  ·  View on CISA ICS-CERT ↗

Rockwell Automation MicroLogix 1400 SNMP Credentials Vulnerability

CVSS 7.3 HIGH

CVEs (1)

Remediations

  • Due to the nature of this product’s firmware update process, this capability cannot be removed from the product. Instead, mitigations are offered to reduce risk of this capability being used by a malicious actor. Rockwell Automation recommends that users using affected versions of the MicroLogix 1400 evaluate and deploy the risk mitigation strategies listed below. When possible, multiple strategies should be employed simultaneously.
  • Utilize the product’s “RUN” keyswitch setting to prevent unauthorized and undesired firmware update operations and other disruptive configuration changes. Utilize proper network infrastructure controls, such as firewalls, to help ensure that SNMP requests from unauthorized sources are blocked. See KB496391KB496391, (https://rockwellautomation.custhelp.com/app/answers/detail/a_id/496391), web site last accessed August 11, 2016, for more information on blocking access to SNMP services.
  • Disable the SNMP service on this product. The SNMP service is enabled by default. See Page 128 in the MicroLogix 1400 product manual, (http://literature.rockwellautomation.com/idc/groups/literature/documents/um/1766-um001_-en-p.pdf), web site last accessed August 11, 2016, for detailed instructions on enabling and disabling SNMP.
  • Note: It will be necessary to re-enable SNMP to update firmware on this product. After the upgrade is complete, disable the SNMP service once again.
  • Note: Changing the SNMP community strings is not an effective mitigation.
  • Minimize network exposure for all control system devices and/or systems and ensure that they are not accessible from the Internet. Locate control system networks and devices behind firewalls, and isolate them from the business network. When remote access is required, use secure methods, such as virtual private networks (VPNs), recognizing that VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize that a VPN is only as secure as the connected devices.

Affected Vendors

Rockwell Automation

Affected Products (6)

Rockwell Automation · 1766-L32BWA vers:all/*
Rockwell Automation · 1766-L32AWA vers:all/*
Rockwell Automation · 1766-L32BXB vers:all/*
Rockwell Automation · 1766-L32BWAA vers:all/*
Rockwell Automation · 1766-L32AWAA vers:all/*
Rockwell Automation · 1766-L32BXBA vers:all/*

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more