← Vulnerability feed

Vulnerability record · CVE-2012-6437 · published 24 January 2013

CVE-2012-6437: Rockwellautomation controllogix controllers improper authentication vulnerability

Rockwellautomation · Controllogix Controllers

The device does not properly authenticate users and the potential exists for a remote user to upload a new firmware image to the Ethernet card, whether it is a corrupt or legitimate firmware image. Successful exploitation of this vulnerability could cause loss of availability, integrity, and confidentiality and a disruption in communications with other connected devices. Rockwell Automation EtherNet/IP products; 1756-ENBT, 1756-EWEB, 1768-ENBT, and 1768-EWEB communication modules; CompactLogix L32E and L35E controllers; 1788-ENBT FLEXLogix adapter; 1794-AENTR FLEX I/O EtherNet/IP adapter; ControlLogix 18 and earlier; CompactLogix 18 and earlier; GuardLogix 18 and earlier; SoftLogix 18 and earlier; CompactLogix controllers 19 and earlier; SoftLogix controllers 19 and earlier; ControlLogix controllers 20 and earlier; GuardLogix controllers 20 and earlier; and MicroLogix 1100 and 1400

9.8 CVSS 3.1 Critical EPSS 7.8% · top 5.5% CWE-287 · Improper authentication
9.8CVSS 3.1 base score, v2 10.0
7.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
17Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

The device does not properly authenticate users and the potential exists for a remote user to upload a new firmware image to the Ethernet card, whether it is a corrupt or legitimate firmware image. Successful exploitation of this vulnerability could cause loss of availability, integrity, and confidentiality and a disruption in communications with other connected devices. Rockwell Automation EtherNet/IP products; 1756-ENBT, 1756-EWEB, 1768-ENBT, and 1768-EWEB communication modules; CompactLogix L32E and L35E controllers; 1788-ENBT FLEXLogix adapter; 1794-AENTR FLEX I/O EtherNet/IP adapter; ControlLogix 18 and earlier; CompactLogix 18 and earlier; GuardLogix 18 and earlier; SoftLogix 18 and earlier; CompactLogix controllers 19 and earlier; SoftLogix controllers 19 and earlier; ControlLogix controllers 20 and earlier; GuardLogix controllers 20 and earlier; and MicroLogix 1100 and 1400

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

17 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-6437 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.5CVE-2012-6439Rockwellautomation controllogix controllers improper access control vulnerabilityWhen an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or P…EPSS 23%7.5CVE-2012-6435Rockwellautomation controllogix controllers improper access control vulnerabilityWhen an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or P…EPSS 33%7.5CVE-2012-6436Rockwellautomation controllogix controllers memory buffer overflow vulnerabilityThe device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port 2222/UDP,…EPSS 27%7.5CVE-2012-6438Rockwellautomation controllogix controllers memory buffer overflow vulnerabilityThe device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port 2222/UDP,…EPSS 27%5.0CVE-2012-6441Rockwell Automation EtherNet/IP modules expose confidential data via crafted CIP packetA specially crafted CIP packet sent to TCP/UDP ports 2222 or 44818 causes Rockwell Automation EtherNet/IP communication modules and controllers to ex…EPSS 57%analysed4.8CVE-2012-6440Rockwellautomation controllogix controllers improper authentication vulnerabilityThe Web server password authentication mechanism used by the products is vulnerable to a MitM and Replay attack. Successful exploitation of this vuln…EPSS 9.3%7.5CVE-2026-42018JFrog Artifactory improper authentication leaks anonymous tokenJFrog Artifactory can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled. Because the token …KEVEPSS 9.8%analysed9.8CVE-2026-82329JFrog Artifactory improper authentication allows admin takeoverJFrog Artifactory contains an improper authentication weakness (CWE-287) that, under default configuration, may let an unauthenticated attacker with …KEVEPSS 14%analysed

Source: NIST National Vulnerability Database (record CVE-2012-6437), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.