CVE-2020-6988 Details
Description
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, A remote, unauthenticated attacker can send a request from the RSLogix 500 software to the victim’s MicroLogix controller. The controller will then respond to the client with used password values to authenticate the user on the client-side. This method of authentication may allow an attacker to bypass authentication altogether, disclose sensitive information, or leak credentials.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.us-cert.gov/ics/advisories/icsa-20-070-06 | CVE | Third Party AdvisoryUS Government Resource |
| https://www.us-cert.gov/ics/advisories/icsa-20-070-06 | [email protected] | Third Party AdvisoryUS Government Resource |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
| CWE-603 | Use of Client-Side Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| rockwellautomation micrologix 1400 a firmware | All versions |
CPE
Remediation
| |
| rockwellautomation micrologix 1400 b firmware | <= 21.001 |
CPE
Remediation
| |
| rockwellautomation micrologix 1400 | All versions |
CPE
Remediation
| |
| rockwellautomation micrologix 1100 firmware | All versions |
CPE
Remediation
| |
| rockwellautomation micrologix 1100 | All versions |
CPE
Remediation
| |
| rockwellautomation rslogix 500 | <= 12.001 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 3, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Mar 20, 2020 | Reanalysis | [email protected] |
| Mar 20, 2020 | Initial Analysis | [email protected] |