The security of our products is important to us as your industrial automation supplier. Rockwell Automation has become aware of threat actor activity targeting internet-exposed PLCs, specifically Rockwell Automation/Allen-Bradley’s MicroLogix1400 series. Threat actors have reportedly targeted these controllers to remotely tamper with device configurations by changing IP addresses and turning on and setting passwords, resulting in a loss of operator view.
We are sharing this to guide customers who are unable to access their MicroLogix™ 1400 controllers because a password has been set that is not known. It explains how to return the controller to a factory default state so that a known good project file can be redownloaded. No CVE is associated with this notice; it is operational recovery guidance rather than a vulnerability disclosure.
Product Description
The MicroLogix™ 1400 from Rockwell Automation is a compact programmable logic controller (PLC) that provides a higher I/O count, faster high-speed counter and pulse-train output, enhanced network capabilities, and a backlit LCD panel. It is programmed and maintained using RSLogix 500® software.
Applicable Products and Solution
Applicable Product |
Applicable Series |
Recovery Solution |
Applicable Catalog Numbers |
MicroLogix™ 1400 Programmable Controller
|
Series A, B, and C |
Clear user application memory via battery removal, then redownload the project file (see procedure below)
|
1766-L32AWA 1766-L32AWAA 1766-L32BWA 1766-L32BWAA 1766-L32BXB 1766-L32BXBA
|
Recovering Access to the Controller
IMPORTANT: The following procedure erases the controller’s program, data, and network (IP) configuration. Ensure you have an offline backup of your project (.RSS) file before proceeding, as the program cannot be recovered from the controller after the reset.
1. Power off the controller.
2. Remove the controller battery 1747-BA connection. Information about installing the battery may be found in the MicroLogix™ 1400 Programmable Controllers User Manual Publication 1766-UM001.
3. Power on the controller.
4. Observe the controller entering a fault state.
5. Power off the controller.
6. Reconnect the battery.
7. The IP address and program are now erased
8. Set the IP address using the LCD panel on the controller.
9. Download your project file to the controller using RSLogix 500®.
Before You Begin
• A current offline backup of the controller project (.RSS) file is required, because the reset erases the program from the controller.
• RSLogix 500® programming software and an appropriate programming cable are required to redownload the project.
Reducing the Risk of Recurrence
After restoring the controller, take the following steps to reduce the likelihood of an unauthorized lockout in the future:
• Do not connect the controller directly to the internet. Remove any public IP address or port-forwarding rule and verify the device is not reachable externally.
• Place the controller behind a firewall within an isolated OT/plant network, separated from the business network.
• Set the controller to RUN mode using built-in LCD keypad interface to block unauthorized changes to logic, configuration, and firmware.
• On MicroLogix™ 1400 Series B, apply firmware FRN 21.002 or later and enable Enhanced Password Security.
• Maintain offline backups of your project files so you can recover quickly from a fault or lockout.
• Disable HTTP server when not required , see PN641 for additional information.
For additional hardening guidance, customers should follow our security best practices
.
Revision History
Revision |
Date |
Description |
1.0 |
7/30/2026 |
Initial release |
Glossary:
• RSLogix 500®: The programming and configuration software used to develop, download, and maintain projects on MicroLogix™ and SLC™ 500 controllers.
Get Up-to-Date Product Security Information
Visit the Rockwell Automation security advisories on the Trust Center page to:
· Subscribe to product security alerts
· Review the current list of Rockwell Automation security advisories
· Report a possible security issue in a Rockwell Automation product
· Learn more about the vulnerability policy
Support
If you have any questions regarding the guidance above and how to apply it, contact TechConnect for help. More information can be found at Contact Us | Rockwell Automation | US.
If you have any questions regarding this notice, please contact PSIRT
Email: PSIRT@rockwellautomation,com
Legal Disclaimer
ROCKWELL AUTOMATION DOES NOT WARRANT THE COMPLETENESS, TIMELINESS OR ACCURACY OF ANY OF THE DATA CONTAINED IN THIS WEB SITE AND MAY MAKE CHANGES THERETO AT ANY TIME IN ITS SOLE DISCRETION WITHOUT NOTICE. FURTHER, ALL INFORMATION CONVEYED HEREBY IS PROVIDED TO USERS "AS IS." IN NO EVENT SHALL ROCKWELL BE LIABLE FOR ANY DAMAGES OF ANY KIND INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS PROFIT OR DAMAGE, EVEN IF ROCKWELL AUTOMATION HAS BEEN ADVISED ON THE POSSIBILITY OF SUCH DAMAGES. ROCKWELL AUTOMATION DISCLAIMS ALL WARRANTIES WHETHER EXPRESSED OR IMPLIED IN RESPECT OF THE INFORMATION (INCLUDING SOFTWARE) PROVIDED HEREBY, INCLUDING THE IMPLIED WARRANTIES OF FITNESS FOR A PARTICULAR PURPOSE, MERCHANTABILITY, AND NON-INFRINGEMENT. Note that certain jurisdictions do not countenance the exclusion of implied warranties; thus, this disclaimer may not apply to you.