First published: Wed Apr 06 2016(Updated: )
IAB.exe in Rockwell Automation Integrated Architecture Builder (IAB) before 9.6.0.8 and 9.7.x before 9.7.0.2 allows remote attackers to execute arbitrary code via a crafted project file.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Rockwell Automation Integrated Architecture Builder | <=9.6.0.7 | |
Rockwell Automation Integrated Architecture Builder | =9.7.0.0 | |
Rockwell Automation Integrated Architecture Builder | =9.7.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2277 has a high severity rating due to its potential to allow remote code execution.
To fix CVE-2016-2277, update Rockwell Automation Integrated Architecture Builder to version 9.6.0.8 or 9.7.0.2 or later.
CVE-2016-2277 affects versions of Integrated Architecture Builder prior to 9.6.0.8 and specific 9.7.x versions before 9.7.0.2.
Yes, CVE-2016-2277 can be exploited remotely through a crafted project file.
Exploitation of CVE-2016-2277 can lead to arbitrary code execution on the affected system.