PT-2017-17999 · Rockwell Automation · Micrologix 1100
Published
2017-09-20
·
Updated
2019-10-09
·
CVE-2017-7924
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Rockwell Automation MicroLogix 1100 controllers version 1763-L16BWA
Rockwell Automation MicroLogix 1100 controllers version 1763-L16AWA
Rockwell Automation MicroLogix 1100 controllers version 1763-L16BBB
Rockwell Automation MicroLogix 1100 controllers version 1763-L16DWD
Description
An issue with improper input validation was found, allowing a remote, unauthenticated attacker to send a specially crafted Programmable Controller Communication Commands (PCCC) packet, potentially causing the controller to enter a denial-of-service condition.
Recommendations
For version 1763-L16BWA, apply the recommended fix from the vendor to prevent the controller from entering a DoS condition.
For version 1763-L16AWA, apply the recommended fix from the vendor to prevent the controller from entering a DoS condition.
For version 1763-L16BBB, apply the recommended fix from the vendor to prevent the controller from entering a DoS condition.
For version 1763-L16DWD, apply the recommended fix from the vendor to prevent the controller from entering a DoS condition.
As a temporary workaround, consider restricting access to the PCCC packet until a patch is available.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Micrologix 1100