CVE-2012-6440 Details
Description
The Web server password authentication mechanism used by the products is vulnerable to a MitM and Replay attack. Successful exploitation of this vulnerability will allow unauthorized access of the product’s Web server to view and alter product configuration and diagnostics information. Rockwell Automation EtherNet/IP products; 1756-ENBT, 1756-EWEB, 1768-ENBT, and 1768-EWEB communication modules; CompactLogix L32E and L35E controllers; 1788-ENBT FLEXLogix adapter; 1794-AENTR FLEX I/O EtherNet/IP adapter; ControlLogix 18 and earlier; CompactLogix 18 and earlier; GuardLogix 18 and earlier; SoftLogix 18 and earlier; CompactLogix controllers 19 and earlier; SoftLogix controllers 19 and earlier; ControlLogix controllers 20 and earlier; GuardLogix controllers 20 and earlier; and MicroLogix 1100 and 1400
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| rockwellautomation controllogix controllers | <= 20 |
CPE
Remediation
| |
| rockwellautomation guardlogix controllers | <= 20 |
CPE
Remediation
| |
| rockwellautomation micrologix | <= 1100 <= 1400 |
CPE
Remediation
| |
| rockwellautomation softlogix controllers | <= 19 |
CPE
Remediation
| |
| rockwellautomation 1756-enbt | All versions |
CPE
Remediation
| |
| rockwellautomation 1756-eweb | All versions |
CPE
Remediation
| |
| rockwellautomation 1768-enbt | All versions |
CPE
Remediation
| |
| rockwellautomation 1768-eweb | All versions |
CPE
Remediation
| |
| rockwellautomation 1794-aentr flex i/o ethernet/ip adapter | All versions |
CPE
Remediation
| |
| rockwellautomation compactlogix | <= 18 |
CPE
Remediation
| |
| rockwellautomation compactlogix controllers | <= 19 |
CPE
Remediation
| |
| rockwellautomation compactlogix l32e controller | All versions |
CPE
Remediation
| |
| rockwellautomation compactlogix l35e controller | All versions |
CPE
Remediation
| |
| rockwellautomation controllogix | <= 18 |
CPE
Remediation
| |
| rockwellautomation flexlogix 1788-enbt adapter | All versions |
CPE
Remediation
| |
| rockwellautomation guardlogix | <= 18 |
CPE
Remediation
| |
| rockwellautomation softlogix | <= 18 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 16, 2026 | CVE Modified | CISA-ADP |
| Jun 16, 2026 | CVE Modified | [email protected] |
| Jun 3, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Status Change | [email protected] |
| Jun 30, 2025 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jan 25, 2013 | Initial Analysis | [email protected] |