Vulnerability CVE-2016-9338


Published: 2017-02-13   Modified: 2017-02-14

Description:
An issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 controller 1763-L16AWA, Series A and B, Version 14.000 and prior versions; 1763-L16BBB, Series A and B, Version 14.000 and prior versions; 1763-L16BWA, Series A and B, Version 14.000 and prior versions; and 1763-L16DWD, Series A and B, Version 14.000 and prior versions. Because of an Incorrect Permission Assignment for Critical Resource, users with administrator privileges may be able to remove all administrative users requiring a factory reset to restore ancillary web server function. Exploitation of this vulnerability will still allow the affected device to function in its capacity as a controller.

CVSS2 => (AV:N/AC:L/Au:S/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4/10
2.9/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
Rockwellautomation -> 1763-l16bbb series b 
Rockwellautomation -> 1763-l16dwd series b 
Rockwellautomation -> 1766-l32bwaa series b 
Rockwellautomation -> 1763-l16dwd series a 
Rockwellautomation -> 1763-l16bbb series a 
Rockwellautomation -> 1766-l32awa series b 
Rockwellautomation -> 1763-l16bwa series b 
Rockwellautomation -> 1766-l32bxb series b 
Rockwellautomation -> 1766-l32bxba series a 
Rockwellautomation -> 1766-l32awa series a 
Rockwellautomation -> 1766-l32bxb series a 
Rockwellautomation -> 1766-l32awaa series a 
Rockwellautomation -> 1766-l32bxba series b 
Rockwellautomation -> 1763-l16awa series b 
Rockwellautomation -> 1766-l32awaa series b 
Rockwellautomation -> 1766-l32bwaa series a 
Rockwellautomation -> 1763-l16awa series a 
Rockwellautomation -> 1766-l32bwa series b 
Rockwellautomation -> 1766-l32bwa series a 
Rockwellautomation -> 1763-l16bwa series a 

 References:
http://www.securityfocus.com/bid/95302
https://ics-cert.us-cert.gov/advisories/ICSA-16-336-06

Copyright 2022, cxsecurity.com

 

Back to Top