Podatność CVE-2016-9338


Publikacja: 2017-02-13   Modyfikacja: 2017-02-14

Opis:
An issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 controller 1763-L16AWA, Series A and B, Version 14.000 and prior versions; 1763-L16BBB, Series A and B, Version 14.000 and prior versions; 1763-L16BWA, Series A and B, Version 14.000 and prior versions; and 1763-L16DWD, Series A and B, Version 14.000 and prior versions. Because of an Incorrect Permission Assignment for Critical Resource, users with administrator privileges may be able to remove all administrative users requiring a factory reset to restore ancillary web server function. Exploitation of this vulnerability will still allow the affected device to function in its capacity as a controller.

CVSS2 => (AV:N/AC:L/Au:S/C:N/I:N/A:P)

Ogólna skala CVSS
Znaczenie
Łatwość wykorzystania
4/10
2.9/10
8/10
Wymagany dostęp
Złożoność ataku
Autoryzacja
Zdalny
Niska
Jednorazowa
Wpływ na poufność
Wpływ na integralność
Wpływ na dostępność
Brak
Brak
Częściowy
Affected software
Rockwellautomation -> 1763-l16bbb series b 
Rockwellautomation -> 1763-l16dwd series b 
Rockwellautomation -> 1766-l32bwaa series b 
Rockwellautomation -> 1763-l16dwd series a 
Rockwellautomation -> 1763-l16bbb series a 
Rockwellautomation -> 1766-l32awa series b 
Rockwellautomation -> 1763-l16bwa series b 
Rockwellautomation -> 1766-l32bxb series b 
Rockwellautomation -> 1766-l32bxba series a 
Rockwellautomation -> 1766-l32awa series a 
Rockwellautomation -> 1766-l32bxb series a 
Rockwellautomation -> 1766-l32awaa series a 
Rockwellautomation -> 1766-l32bxba series b 
Rockwellautomation -> 1763-l16awa series b 
Rockwellautomation -> 1766-l32awaa series b 
Rockwellautomation -> 1766-l32bwaa series a 
Rockwellautomation -> 1763-l16awa series a 
Rockwellautomation -> 1766-l32bwa series b 
Rockwellautomation -> 1766-l32bwa series a 
Rockwellautomation -> 1763-l16bwa series a 

 Referencje:
http://www.securityfocus.com/bid/95302
https://ics-cert.us-cert.gov/advisories/ICSA-16-336-06

Copyright 2024, cxsecurity.com

 

Back to Top