CVE-2016-5645
Severity CVSS v4.0:
Pending analysis
Type:
CWE-284
Improper Access Control
Publication date:
24/08/2016
Last modified:
12/04/2025
Description
Rockwell Automation MicroLogix 1400 PLC 1766-L32BWA, 1766-L32AWA, 1766-L32BXB, 1766-L32BWAA, 1766-L32AWAA, and 1766-L32BXBA devices have a hardcoded SNMP community, which makes it easier for remote attackers to load arbitrary firmware updates by leveraging knowledge of this community.
Impact
Base Score 3.x
7.30
Severity 3.x
HIGH
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:h:rockwellautomation:1766-l32awa:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:rockwellautomation:1766-l32awaa:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:rockwellautomation:1766-l32bwa:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:rockwellautomation:1766-l32bwaa:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:rockwellautomation:1766-l32bxb:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:rockwellautomation:1766-l32bxba:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page