Rewterz

Rewterz Threat Advisory – Multiple VMware Products Vulnerabilities

May 26, 2021
Rewterz

Rewterz Threat Alert – Dridex Banking Malware – Active IOCs

May 26, 2021

Rewterz Threat Advisory – CVE-2021-32926 – ICS: Rockwell Automation Micro800 and MicroLogix 1400

Severity

Medium

Analysis Summary

CVE-2021-32926

The Micro800 and MicroLogix 1400 vulnerability allows an attacker to intercept messages that include a legitimate, new password hash and replace the hash with an illegitimate one. This happens when an authenticated password change request takes place. A denial-of-service condition occurs as the user is no longer able to authenticate to the controller.

Impact

Denial of Service

Affected Vendors

Rockwell Automation

Affected Products

  • Micro800: All versions
  • MicroLogix 1400: Version 21 and later

Remediation

Refer to vendor advisory for the complete list of affected products and their respective patches at https://us-cert.cisa.gov/ics/advisories/icsa-21-145-02

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.