peter bassill · operator
$ cve CVE-2012-6437 JSON

CVE-2012-6437

9.8
CRITICAL · CVSS 3.1 · EPSS 7.8% (pctl 95)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The device does not properly authenticate users and the potential exists for a remote user to upload a new firmware image to the Ethernet card, whether it is a corrupt or legitimate firmware image. Successful exploitation of this vulnerability could cause loss of availability, integrity, and confidentiality and a disruption in communications with other connected devices. Rockwell Automation EtherNet/IP products; 1756-ENBT, 1756-EWEB, 1768-ENBT, and 1768-EWEB communication modules; CompactLogix L32E and L35E controllers; 1788-ENBT FLEXLogix adapter; 1794-AENTR FLEX I/O EtherNet/IP adapter; ControlLogix 18 and earlier; CompactLogix 18 and earlier; GuardLogix 18 and earlier; SoftLogix 18 and earlier; CompactLogix controllers 19 and earlier; SoftLogix controllers 19 and earlier; ControlLogix controllers 20 and earlier; GuardLogix controllers 20 and earlier; and MicroLogix 1100 and 1400

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS7.85% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploitnone known
Published2013-01-24
Last modified2026-06-16

Affected (17)

VendorProduct
rockwellautomation1756-enbt
rockwellautomation1756-eweb
rockwellautomation1768-enbt
rockwellautomation1768-eweb
rockwellautomation1794-aentr flex i\/o ethernet\/ip adapter
rockwellautomationcompactlogix
rockwellautomationcompactlogix controllers
rockwellautomationcompactlogix l32e controller
rockwellautomationcompactlogix l35e controller
rockwellautomationcontrollogix
rockwellautomationcontrollogix controllers
rockwellautomationflexlogix 1788-enbt adapter
rockwellautomationguardlogix
rockwellautomationguardlogix controllers
rockwellautomationmicrologix
rockwellautomationsoftlogix
rockwellautomationsoftlogix controllers

References

→ the Explorer  ·  watch your stack  ·  NVD