First published: Mon Feb 13 2017(Updated: )
An issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 controller 1763-L16AWA, Series A and B, Version 14.000 and prior versions; 1763-L16BBB, Series A and B, Version 14.000 and prior versions; 1763-L16BWA, Series A and B, Version 14.000 and prior versions; and 1763-L16DWD, Series A and B, Version 14.000 and prior versions. Because of an Incorrect Permission Assignment for Critical Resource, users with administrator privileges may be able to remove all administrative users requiring a factory reset to restore ancillary web server function. Exploitation of this vulnerability will still allow the affected device to function in its capacity as a controller.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Rockwell Automation 1763-L16AWA Series A | <=14.000 | |
Rockwell Automation 1763-L16AWA Series B | <=14.000 | |
Rockwell Automation 1763-L16BBB Series A | <=14.000 | |
Rockwell Automation 1763-L16BBB Series B | <=14.000 | |
Rockwell Automation 1763-L16BWA Series A | <=14.000 | |
Rockwell Automation 1763-L16AWA Series B | <=14.000 | |
Rockwell Automation 1763-L16DWD Series A | <=14.000 | |
Rockwell Automation 1763-L16DWD Series B | <=14.000 | |
Rockwell Automation 1766-L32AWA Series A | <=15.004 | |
Rockwell Automation 1766-L32AWA Series B | <=15.004 | |
Rockwell Automation 1766-L32AWAA Series A | <=15.004 | |
Rockwell Automation 1766-L32AWAA Series B | <=15.004 | |
Rockwell Automation 1766-L32BWA Series A | <=15.004 | |
Rockwell Automation 1766-L32BWA Series B | <=15.004 | |
Rockwell Automation 1766-L32BWAA Series A | <=15.004 | |
Rockwell Automation 1766-L32BWAA Series A | <=15.004 | |
Rockwell Automation 1766-L32BXB Series A | <=15.004 | |
Rockwell Automation 1766-L32BXB Series B | <=15.004 | |
Rockwell Automation 1766-L32BXBA Series A | <=15.004 | |
Rockwell Automation 1766-L32BXBA Series B | <=15.004 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9338 has a CVSS score indicating a high severity vulnerability that could lead to unauthorized access.
To fix CVE-2016-9338, upgrade the Rockwell Automation MicroLogix 1100 controllers to the latest firmware version that addresses this vulnerability.
CVE-2016-9338 affects Rockwell Automation MicroLogix 1100 controllers including models 1763-L16AWA, 1763-L16BBB, 1763-L16BWA, and 1763-L16DWD with version 14.000 and earlier.
The risks of CVE-2016-9338 include potential remote attacks that could exploit the vulnerability to gain unauthorized access to the control systems.
While a permanent fix is recommended, implementing network segmentation and access controls can serve as temporary workarounds against CVE-2016-9338.