1. EXECUTIVE SUMMARY
CVSS v3 8.6
ATTENTION: Exploitable remotely/low skill level to exploit
Vendor: Automation
Equipment: MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules
Vulnerability: Missing Authentication for Critical Function
2. REPOSTED INFORMATION
This advisory was originally posted to the HSIN ICS-CERT library on November 6, 2018, and is being released to the NCCIC/ICS-CERT website.
3. RISK EVALUATION
Successful exploitation of this vulnerability could allow an unauthenticated attacker to modify system settings and cause a loss of communication between the device and the system.