« Volver al listado

CVE-2020-6111

Estado: ModificadaAlta (7.5)—

An exploitable denial-of-service vulnerability exists in the IPv4 functionality of Allen-Bradley MicroLogix 1100 Programmable Logic Controller Systems Series B FRN 16.000, Series B FRN 15.002, Series B FRN 15.000, Series B FRN 14.000, Series B FRN 13.000, Series B FRN 12.000, Series B FRN 11.000 and Series B FRN 10.000. A specially crafted packet can cause a major error, resulting in a denial of service. An attacker can send a malicious packet to trigger this vulnerability.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-6111",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "talos-cna@cisco.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "talos-cna@cisco.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Allen-Bradley",
          "versions": [
            {
              "status": "affected",
              "version": "Allen-Bradley MicroLogix 1100 Programmable Logic Controller Systems Series B FRN 10.000, Allen-Bradley MicroLogix 1100 Programmable Logic Controller Systems Series B FRN 11.000, Allen-Bradley MicroLogix 1100 Programmable Logic Controller Systems Series B FRN 12.000, Allen-Bradley MicroLogix 1100 Programmable Logic Controller Systems Series B FRN 13.000, Allen-Bradley MicroLogix 1100 Programmable Logic Controller Systems Series B FRN 14.000, Allen-Bradley MicroLogix 1100 Programmable Logic Controller Systems Series B FRN 15.000, Allen-Bradley MicroLogix 1100 Programmable Logic Controller Systems Series B FRN 15.002, Allen-Bradley MicroLogix 1100 Programmable Logic Controller Systems Series B FRN 16.000"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-12-03T13:15:10.477",
  "references": [
    {
      "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2020-1057",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "talos-cna@cisco.com"
    },
    {
      "url": "https://us-cert.cisa.gov/ics/advisories/icsa-21-047-02",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "talos-cna@cisco.com"
    },
    {
      "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2020-1057",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://us-cert.cisa.gov/ics/advisories/icsa-21-047-02",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "talos-cna@cisco.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-189"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An exploitable denial-of-service vulnerability exists in the IPv4 functionality of Allen-Bradley MicroLogix 1100 Programmable Logic Controller Systems Series B FRN 16.000, Series B FRN 15.002, Series B FRN 15.000, Series B FRN 14.000, Series B FRN 13.000, Series B FRN 12.000, Series B FRN 11.000 and Series B FRN 10.000. A specially crafted packet can cause a major error, resulting in a denial of service. An attacker can send a malicious packet to trigger this vulnerability."
    },
    {
      "lang": "es",
      "value": "Se presenta una vulnerabilidad explotable de denegación de servicio en la funcionalidad IPv4 de Allen-Bradley MicroLogix 1100 Programmable Logic Controller Systems Series B FRN 16.000, Series B FRN 15.002, Series B FRN 15.000, Series B FRN 14.000, Series B FRN 13.000, Series B FRN 12.000, Series B FRN 11.000 y Series B FRN 10.000. Un paquete especialmente diseñado puede causar un error importante, resultando en una denegación de servicio. Un atacante puede enviar un paquete malicioso para desencadenar esta vulnerabilidad"
    }
  ],
  "lastModified": "2026-06-17T03:22:42.417",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:rockwellautomation:micrologix_1100_b_firmware:10.000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F34B3F59-E1DE-486D-A8DC-3FF455EDFCDC"
            },
            {
              "criteria": "cpe:2.3:o:rockwellautomation:micrologix_1100_b_firmware:11.000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A41A499B-AAE2-4722-9F81-6F2F5BD070AD"
            },
            {
              "criteria": "cpe:2.3:o:rockwellautomation:micrologix_1100_b_firmware:12.000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5AC73C0A-9CA5-40D7-9746-A62CE76D197D"
            },
            {
              "criteria": "cpe:2.3:o:rockwellautomation:micrologix_1100_b_firmware:13.000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C0166D62-5394-41F6-9A03-538BB8A03CE1"
            },
            {
              "criteria": "cpe:2.3:o:rockwellautomation:micrologix_1100_b_firmware:14.000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C358A996-F06F-4CAA-8445-EC7317FEF9B1"
            },
            {
              "criteria": "cpe:2.3:o:rockwellautomation:micrologix_1100_b_firmware:15.000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EC8A35E3-8249-4C13-B62C-2265D9A9EAF9"
            },
            {
              "criteria": "cpe:2.3:o:rockwellautomation:micrologix_1100_b_firmware:15.002:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BAAE164B-3963-4890-B709-A56BA7FF4FED"
            },
            {
              "criteria": "cpe:2.3:o:rockwellautomation:micrologix_1100_b_firmware:16.000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8E0F12BD-EDC4-4CD7-9C03-E31410B3AA7E"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:rockwellautomation:micrologix_1100:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "DA42C7F4-EEC1-44D2-BD46-237969FF6E1A"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "talos-cna@cisco.com"
}