CVE-2017-7898: Critical severity rockwellautomation 1763-l16awa Series A vulnerability
An Improper Restriction of Excessive Authentication Attempts issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prior versions; 1763-L16BBB, Series A and B, Version 16.00 and prior versions; 1763-L16BWA, Series A and B, Version 16.00 and prior versions; and 1763-L16DWD, Series A and B, Version 16.00 and prior versions and Allen-Bradley MicroLogix 1400 programmable logic controllers 1766-L32AWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWAA, Series A and B, Version 16.00 and prior versions; 1766-L32BXB, Series A and B, Version 16.00 and prior versions; 1766-L32BXBA, Series A and B, Version 16.00 and prior versions; and 1766-L32AWAA, Series A and B, Version 16.00 and prior versions. There are no penalties for repeatedly entering incorrect passwords.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7898?
CVE-2017-7898 has a severity rating that indicates a significant security risk due to improper restriction of excessive authentication attempts.
How do I fix CVE-2017-7898?
To fix CVE-2017-7898, update the affected Rockwell Automation MicroLogix 1100 devices to the latest firmware version beyond 16.00.
Which devices are affected by CVE-2017-7898?
CVE-2017-7898 affects Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers including models 1763-L16AWA and 1763-L16BBB, among others.
What type of vulnerability is CVE-2017-7898?
CVE-2017-7898 is classified as an improper restriction of excessive authentication attempts vulnerability.
Can CVE-2017-7898 be exploited remotely?
Yes, CVE-2017-7898 can potentially be exploited remotely to perform brute-force attacks on authentication.