Overview
The Rockwell ControlLogix 1756-ENBT/A EtherNet/IP Bridge web interface contains a URL redirection vulnerability.
Description
The Rockwell Logix Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge uses a web interface to display log files and status information. This web interface contains a URL redirection vulnerability. To exploit this issue, an attacker would need to convince an operator to open on a specially crafted URL. |
Impact
An attacker may be able to redirect a user's browser to an another website. |
Solution
We are currently unaware of a practical solution to this problem. Until updated firmware is available, we recommend that administrators implement the below workaround. |
Do not allow remote access |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Daniel Peck of Digital Bond, Inc. for reporting this issue.
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | None |
Severity Metric: | 0.21 |
Date Public: | 2009-02-01 |
Date First Published: | 2009-02-05 |
Date Last Updated: | 2010-01-11 05:41 UTC |
Document Revision: | 36 |