Overview
The Rockwell ControlLogix 1756-ENBT/A EtherNet/IP Bridge web interface contains a URL redirection vulnerability.
Description
The Rockwell Logix Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge uses a web interface to display log files and status information. This web interface contains a URL redirection vulnerability. To exploit this issue, an attacker would need to convince an operator to open on a specially crafted URL.  | 
Impact
An attacker may be able to redirect a user's browser to an another website.  | 
Solution
We are currently unaware of a practical solution to this problem. Until updated firmware is available, we recommend that administrators implement the below workaround.  | 
Do not allow remote access  | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental | 
References
Acknowledgements
Thanks to Daniel Peck of Digital Bond, Inc. for reporting this issue.
This document was written by Ryan Giobbi.
Other Information
| CVE IDs: | None | 
| Severity Metric: | 0.21 | 
| Date Public: | 2009-02-01 | 
| Date First Published: | 2009-02-05 | 
| Date Last Updated: | 2010-01-11 05:41 UTC | 
| Document Revision: | 36 |