CVE-2016-9338: Low severity rockwellautomation 1763-l16awa Series A vulnerability
An issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 controller 1763-L16AWA, Series A and B, Version 14.000 and prior versions; 1763-L16BBB, Series A and B, Version 14.000 and prior versions; 1763-L16BWA, Series A and B, Version 14.000 and prior versions; and 1763-L16DWD, Series A and B, Version 14.000 and prior versions. Because of an Incorrect Permission Assignment for Critical Resource, users with administrator privileges may be able to remove all administrative users requiring a factory reset to restore ancillary web server function. Exploitation of this vulnerability will still allow the affected device to function in its capacity as a controller.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9338?
CVE-2016-9338 has a CVSS score indicating a high severity vulnerability that could lead to unauthorized access.
How do I fix CVE-2016-9338?
To fix CVE-2016-9338, upgrade the Rockwell Automation MicroLogix 1100 controllers to the latest firmware version that addresses this vulnerability.
Which devices are affected by CVE-2016-9338?
CVE-2016-9338 affects Rockwell Automation MicroLogix 1100 controllers including models 1763-L16AWA, 1763-L16BBB, 1763-L16BWA, and 1763-L16DWD with version 14.000 and earlier.
What are the potential risks of CVE-2016-9338?
The risks of CVE-2016-9338 include potential remote attacks that could exploit the vulnerability to gain unauthorized access to the control systems.
Is there a workaround for CVE-2016-9338?
While a permanent fix is recommended, implementing network segmentation and access controls can serve as temporary workarounds against CVE-2016-9338.