CVE-2018-17924

HIGHCVSS 8.6/10EPSS 4.30%

Last modified

CVE-2018-17924 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. Rockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unauthenticated, remote threat actor could send a CIP connection request to an affected device, and upon successful connection, send a new IP configuration to the affected device even if the controller in the system is set to Hard RUN mode. When the affected device accepts this new IP configuration, a loss of communication occurs between the device and the rest of the system as the system traffic is still attempting to communicate with the device via the overwritten IP address.. EPSS estimates a 4.30% chance of exploitation in the next 30 days.

Description

Rockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unauthenticated, remote threat actor could send a CIP connection request to an affected device, and upon successful connection, send a new IP configuration to the affected device even if the controller in the system is set to Hard RUN mode. When the affected device accepts this new IP configuration, a loss of communication occurs between the device and the rest of the system as the system traffic is still attempting to communicate with the device via the overwritten IP address.

Metrics

CVSS 3.1
8.6/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

EPSS Probability
4.30%

89.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
RockwellautomationMicrologix 1400 FirmwareAll versions
Rockwellautomation1756-Enbt FirmwareAll versions
Rockwellautomation1756-Eweb Series A FirmwareAll versions
Rockwellautomation1756-Eweb Series B FirmwareAll versions
Rockwellautomation1756-En2f Series A FirmwareAll versions
Rockwellautomation1756-En2f Series B FirmwareAll versions
Rockwellautomation1756-En2f Series C Firmware<= 10.10
Rockwellautomation1756-En2t Series A FirmwareAll versions
Rockwellautomation1756-En2t Series B FirmwareAll versions
Rockwellautomation1756-En2t Series C FirmwareAll versions
Rockwellautomation1756-En2t Series D Firmware<= 10.10
Rockwellautomation1756-En2tr Series A FirmwareAll versions
Rockwellautomation1756-En2tr Series B FirmwareAll versions
Rockwellautomation1756-En2tr Series C Firmware<= 10.10
Rockwellautomation1756-En3tr Series A FirmwareAll versions
Rockwellautomation1756-En3tr Series B Firmware<= 10.10

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-17924?
Rockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unauthenticated, remote threat actor could send a CIP connection request to an affected device, and upon successful connection, send a new IP configuration to the affected device even if the controller in the system is set to Hard RUN mode. When the affected device accepts this new IP configuration, a loss of communication occurs between the device and the rest of the system as the system traffic is still attempting to communicate with the device via the overwritten IP address.
How severe is CVE-2018-17924?
CVE-2018-17924 has a CVSS score of 8.6/10 (HIGH severity). The EPSS model estimates a 4.30% probability of exploitation in the next 30 days.
How do I fix CVE-2018-17924?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-17924?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST