← Back to home
ICSA-21-047-02  ·  Published 2021-02-16  ·  View on CISA ICS-CERT ↗

Rockwell Automation Allen-Bradley Micrologix 1100

CVSS 7.5 HIGH

Risk Summary

Successful exploitation of this vulnerability could result in denial-of-service conditions.

CVEs (1)

Remediations

  • Rockwell Automation recommends users of MicroLogix 1100 migrate to MicroLogix 1400 and apply firmware v21.006 or later. Please see Rockwell Automation's publication number, PN1548, for more information. Rockwell Automation recommends the following network-based vulnerability mitigations for embedded products
  • Utilize proper network infrastructure controls, such as firewalls, to help ensure traffic from unauthorized sources is blocked.
  • Consult the product documentation for specific features, such as a hardware key mode setting, to which may be used to block unauthorized changes, etc.
  • Block all traffic to EtherNet/IP or other CIP protocol-based devices from outside the manufacturing zone by blocking or restricting access to TCP and UDP Port 2222 and Port 44818 using proper network infrastructure controls, such as firewalls, UTM devices, or other security appliances. For more information on TCP/UDP ports used by Rockwell Automation products, see Knowledgebase Article ID BF7490
  • Minimize network exposure for all control system devices and/or systems and ensure they are not accessible from the Internet. For further information about the risks of unprotected Internet accessible control systems, please see Knowledgebase Article ID PN715
  • Locate control system networks and devices behind firewalls and isolate them from the business network.
  • When remote access is required, use secure methods, such as virtual private networks (VPNs), recognizing that VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize a VPN is only as secure as the connected devices.

Affected Vendors

Rockwell Automation

Affected Products (1)

Rockwell Automation · Allen-Bradley MicroLogix 1100 1.0

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more