CVE detail
CVE-2020-6990 — CVE-2020-6990
Published 2020-03-16 · Modified 2026-06-17 · Vendor rockwellautomation · Product micrologix_1400_a_firmware · Source nvd
CRITICAL
severity
CVSS-derived band
0.0437
EPSS probability
exploitation probability, 30d
90.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic key utilized to help protect the account password is hard coded into the RSLogix 500 binary file. An attacker could identify cryptographic keys and use it for further cryptographic attacks that could ultimately lead to a remote attacker gaining unauthorized access to the controller.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References