CVE-2017-7924
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
20/09/2017
Last modified:
20/04/2025
Description
An Improper Input Validation issue was discovered in Rockwell Automation MicroLogix 1100 controllers 1763-L16BWA, 1763-L16AWA, 1763-L16BBB, and 1763-L16DWD. A remote, unauthenticated attacker could send a single, specially crafted Programmable Controller Communication Commands (PCCC) packet to the controller that could potentially cause the controller to enter a DoS condition.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:rockwellautomation:1763-l16bwa_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:rockwellautomation:1763-l16bwa:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:rockwellautomation:1763-l16awa_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:rockwellautomation:1763-l16awa:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:rockwellautomation:1763-l16bbb_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:rockwellautomation:1763-l16bbb:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:rockwellautomation:1763-l16dwd_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:rockwellautomation:1763-l16dwd:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page