CVE-2016-9334: High severity rockwellautomation 1763-l16awa Series A vulnerability
An issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 controller 1763-L16AWA, Series A and B, Version 14.000 and prior versions; 1763-L16BBB, Series A and B, Version 14.000 and prior versions; 1763-L16BWA, Series A and B, Version 14.000 and prior versions; and 1763-L16DWD, Series A and B, Version 14.000 and prior versions. User credentials are sent to the web server in clear text, which may allow an attacker to discover the credentials if they are able to observe traffic between the web browser and the server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9334?
The severity of CVE-2016-9334 is categorized as high due to potential exposure to remote code execution.
How do I fix CVE-2016-9334?
To fix CVE-2016-9334, upgrade your Rockwell Automation Allen-Bradley MicroLogix 1100 controller firmware to version 14.001 or later.
Which devices are affected by CVE-2016-9334?
CVE-2016-9334 affects various series of Rockwell Automation Allen-Bradley MicroLogix 1100 controllers, including models 1763-L16AWA, 1763-L16BBB, 1763-L16BWA, and 1763-L16DWD with version 14.000 or prior.
What type of vulnerability is CVE-2016-9334?
CVE-2016-9334 is a remote code execution vulnerability that can allow an attacker to execute arbitrary code on the affected controllers.
Is there a mitigation for CVE-2016-9334?
As a mitigation for CVE-2016-9334, it is recommended that users implement network segmentation and restrict access to the affected devices.