High severity7.5NVD Advisory· Published Mar 16, 2020· Updated Jun 17, 2026
CVE-2020-6988
CVE-2020-6988
Description
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, A remote, unauthenticated attacker can send a request from the RSLogix 500 software to the victim’s MicroLogix controller. The controller will then respond to the client with used password values to authenticate the user on the client-side. This method of authentication may allow an attacker to bypass authentication altogether, disclose sensitive information, or leak credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:a:rockwellautomation:rslogix_500:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:rockwellautomation:rslogix_500:*:*:*:*:*:*:*:*range: <=12.001
- (no CPE)range: <=v12.001
cpe:2.3:o:rockwellautomation:micrologix_1100_firmware:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:rockwellautomation:micrologix_1100_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:rockwellautomation:micrologix_1400_a_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:rockwellautomation:micrologix_1400_b_firmware:*:*:*:*:*:*:*:*range: <=21.001
- Rockwell Automation/MicroLogix 1400 Controllers Series B, MicroLogix 1100 Controller, RSLogix 500 Softwaredescription
- Range: all versions
- Range: <=v21.001
Patches
Vulnerability mechanics
References
1- www.us-cert.gov/ics/advisories/icsa-20-070-06nvdThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.