Loading

IMPORTANT NOTICE: Restoring Access to MicroLogix™ 1400 and MicroLogix™ 1100 Controllers When the Password Is Unknown, and Hardening Guidance

Advisory ID:
SD1790
Published Date:
July 30, 2026
Last Updated:
August 10, 2026
Revision Number:
4.0
Known Exploited Vulnerability (KEV):
No
Corrected:
No
Workaround:
Yes
Summary

The security of our products is important to us as your industrial automation supplier. Rockwell Automation has become aware of threat actor activity targeting internet-exposed PLCs, specifically Rockwell Automation/Allen-Bradley’s MicroLogix™ 1400 & MicroLogix™ 1100 series. Threat actors have reportedly targeted these controllers to remotely tamper with device configurations by changing IP addresses and turning on and setting passwords where no passwords were previously set, resulting in a loss of operator view. This activity is described in the FBI Public Service Announcement (PSA), Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, Causing Operational Disruptions, issued July 30, 2026.

 

We are sharing this to guide for customers who are unable to access their MicroLogix™ 1400 & MicroLogix™ 1100 controllers because a password has been set that is not known. Reports indicate that threat actors are enabling password protection on affected controllers where no password had previously been enabled or configured. It explains how to return the controller to a factory default state so that a known good project file can be redownloaded. No CVE is associated with this notice; it is operational recovery guidance and hardening steps rather than a vulnerability disclosure.

 

We also provide a list of primary risk mitigation steps that asset owners can take to secure and harden their OT deployments. Setting a password alone is not sufficient mitigation and should be combined with additional hardening steps referenced in this document. We provide guidance on how to identify and remove devices from the public internet while recognizing that some OT environments require secure, remote access such as a hardened VPN or other solution.

 

Product Description

The MicroLogix™ 1400 and MicroLogix™ 1100 from Rockwell Automation are compact programmable logic controllers (PLCs) designed for a wide range of industrial automation applications. The MicroLogix™ 1400 provides a higher I/O count, faster high-speed counter and pulse-train output capabilities, enhanced networking features, and a backlit LCD panel. Both controllers are programmed and maintained using RSLogix 500® software.

 

Applicable Products and Solution

Applicable Product

Applicable Series

Recovery Solution

Applicable Catalog Numbers

MicroLogix™ 1400 Programmable Controller

 

Series A, B, and C

Clear user application memory via battery removal, then redownload the project file (see procedure below)

 

1766-L32AWA

1766-L32AWAA

1766-L32BWA

1766-L32BWAA

1766-L32BXB

1766-L32BXBA

 

MicroLogix™ 1100 Programmable Controller

 

Series A, B, and C

Set the controller to Program mode using the built-in LCD, then update firmware using ControlFLASH™ over a DF1 serial connection to clear the user program and password, and redownload the project file (see procedure below)

 

1763-L16AWA

1763-L16BWA

1763-L16BBB

1763-L16DWD

 

 

Recovering Access to the MicroLogix™ 1400 Controller

IMPORTANT: The following procedure erases the controller’s program, data, and network (IP) configuration. Ensure that you have an offline backup of your project (.RSS) file before proceeding, as the program cannot be recovered from the controller after the reset.

1.      Power off the controller.

2.      Remove the controller battery 1747-BA connection. Information about installing the battery may be found in the MicroLogix™ 1400 Programmable Controllers User Manual Publication 1766-UM001.

3.      Power on the controller.

4.      Observe the controller entering a fault state.

5.      Power off the controller.

6.      Reconnect the battery.

7.      The IP address and program are now erased

8.      Set the IP address using the LCD panel on the controller.

9.      Download your project file to the controller using RSLogix 500®.

Recovering Access to the MicroLogix™ 1100 Controller

IMPORTANT: ControlFLASH™ over Ethernet is not supported.

1.      Place the controller into Program mode using the LCD.

2.      Connect the PM02 serial cable to the controller. If the computer does not have a serial port, use a USB-to-serial adapter.

3.      Using ControlFLASH™, perform a firmware update over the DF1 serial connection.

4.      The firmware update process will clear the user program and any configured controller password, restoring access to the device.

 

 

Before You Begin

•         A current offline backup of the controller project (.RSS) file is required, because the reset erases the program from the controller.

•         RSLogix 500® programming software and an appropriate programming cable are required to redownload the project.

 

Important Hardening Guidance

Setting or changing the controller password following recovery is not sufficient by itself nor the primary mitigation to defend against this activity. After restoring the controller, the following hardening steps are recommended as primary mitigations to strengthen your OT security posture, and reduce the risk of unauthorized activity in the future:

•         Do not connect the controller directly to the internet. Remove any public IP address or port-forwarding rule and verify that the device is not reachable externally. Refer to the following resources on how to identify exposed assets and disconnect them from the public internet:

•   Rockwell Automation | Advisory on web search tools that identify ICS devices and systems connected to the Internet

•   CISA | NSA and CISA Recommend Immediate Actions to Reduce Exposure Across Operational Technologies and Control Systems

•   CISA | How-to Guide: Stuff Off Shodan

•         Devices that require remote access should leverage a VPN or other secure remote access solution rather than direct internet exposure, and ensure that access is restricted to authorized users.

•         Minimize network exposure for all control system devices and locate them behind firewalls within an isolated OT/plant network, separated from the business network, as part of a defense-in-depth security architecture.

•         Limit controller communication to trusted engineering workstations and known IP addresses using firewall rules or access control lists.

•         Set the controller to RUN mode using built-in LCD keypad interface to block unauthorized changes to logic, configuration, and firmware.

•         On MicroLogix™ 1400 Series B, apply firmware FRN 21.002 or later and enable Enhanced Password Security.

•         Maintain current offline backups of project files and controller configuration so you can recover quickly from a fault, lockout, or unauthorized change.

•         Monitor network and controller logs for unexpected connection attempts, mode changes, or download activity, and investigate anomalies promptly.

•         Disable HTTP server when not required, see PN641 for additional information.

•         Keep controllers and software updated to the latest available firmware and software versions to benefit from the most current security protections.

•         Monitor the Rockwell Automation Trust Center Security Advisories page regularly and subscribe to alerts to stay informed of newly disclosed vulnerabilities affecting your products.

 

For additional hardening guidance, customers should follow our security best practices.

Revision History

Revision

Date

Description

1.0

7/30/2026

Initial release

2.0

7/31/2026

Added MicroLogix™ 1100 instruction

3.0

8/3/2026

Added additional hardening guidance

4.0

8/10/2026

Clarified that setting the password alone is not the primary mitigation

 

Added additional resources on identifying and removing exposed assets from public internet.

 

Added additional hardening guidance for secure remote access.

 

Glossary:

•         RSLogix 500®: The programming and configuration software used to develop, download, and maintain projects on MicroLogix™ and SLC™ 500 controllers.

 

Get Up-to-Date Product Security Information

Visit the Rockwell Automation security advisories on the Trust Center page to:

·         Subscribe to product security alerts

·         Review the current list of Rockwell Automation security advisories

·         Report a possible security issue in a Rockwell Automation product

·         Learn more about the vulnerability policy

 

Support

If you have any questions regarding the guidance above and how to apply it, contact TechConnect for help. More information can be found at Contact Us | Rockwell Automation | US.

If you have any questions regarding this notice, please contact PSIRT
 Email: PSIRT@rockwellautomation,com

 

Legal Disclaimer

ROCKWELL AUTOMATION DOES NOT WARRANT THE COMPLETENESS, TIMELINESS OR ACCURACY OF ANY OF THE DATA CONTAINED IN THIS WEB SITE AND MAY MAKE CHANGES THERETO AT ANY TIME IN ITS SOLE DISCRETION WITHOUT NOTICE. FURTHER, ALL INFORMATION CONVEYED HEREBY IS PROVIDED TO USERS "AS IS." IN NO EVENT SHALL ROCKWELL BE LIABLE FOR ANY DAMAGES OF ANY KIND INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS PROFIT OR DAMAGE, EVEN IF ROCKWELL AUTOMATION HAS BEEN ADVISED ON THE POSSIBILITY OF SUCH DAMAGES. ROCKWELL AUTOMATION DISCLAIMS ALL WARRANTIES WHETHER EXPRESSED OR IMPLIED IN RESPECT OF THE INFORMATION (INCLUDING SOFTWARE) PROVIDED HEREBY, INCLUDING THE IMPLIED WARRANTIES OF FITNESS FOR A PARTICULAR PURPOSE, MERCHANTABILITY, AND NON-INFRINGEMENT. Note that certain jurisdictions do not countenance the exclusion of implied warranties; thus, this disclaimer may not apply to you.

Rockwell Automation Home
Copyright ©2022 Rockwell Automation, Inc.
  1. Chevron LeftChevron Left Rockwell Automation Home
  2. Chevron LeftChevron Left Trust Center
  3. Chevron LeftChevron Left Industrial Security Adv
  4. Chevron LeftChevron Left Industrial Security Advisory Detail
Please update your cookie preferences to continue.
This feature requires cookies to enhance your experience. Please update your preferences to allow for these cookies:
  • Social Media Cookies
  • Functional Cookies
  • Performance Cookies
  • Marketing Cookies
  • All Cookies
You can update your preferences at any time. For more information please see our {0} Privacy Policy
CloseClose