CVE-2016-2279
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD
Description
Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* before 28.011+ allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected (23)
Products: Rockwellautomation: Compactlogix 1769 L16er Bb1b Firmware, Compactlogix 1769 L18er Bb1b Firmware, Compactlogix 1769 L18erm Bb1b Firmware, Compactlogix 1769 L24er Qb1b Firmware, Compactlogix 1769 L24er Qbfc1b Firmware, Compactlogix 1769 L27erm Qbfc1b Firmware, Compactlogix 1769 L30er Firmware, Compactlogix 1769 L30erm Firmware, Compactlogix 1769 L30er Nse Firmware, Compactlogix 1769 L33er Firmware, Compactlogix 1769 L33erm Firmware, Compactlogix 1769 L36erm Firmware, Compactlogix 1769 L23e Qb1b Firmware, Compactlogix 1769 L23e Qbfc1b Firmware, Compactlogix 1756 En2f Series A Firmware, Compactlogix 1756 En2f Series B Firmware, Compactlogix 1756 En2t Series A Firmware, Compactlogix 1756 En2t Series B Firmware, Compactlogix 1756 En2t Series C Firmware, Compactlogix 1756 En2t Series D Firmware, Compactlogix 1756 En2tr Series A Firmware, Compactlogix 1756 En2tr Series B Firmware, Compactlogix 1756 En3tr Series A Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 27.011 |
| Running on/with | Platform Versions |
|---|---|
Rockwellautomation Compactlogix 1769 L16er Bb1b | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 27.011 |
| Running on/with | Platform Versions |
|---|---|
Rockwellautomation Compactlogix 1769 L18er Bb1b | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 27.011 |
| Running on/with | Platform Versions |
|---|---|
Rockwellautomation Compactlogix 1769 L18erm Bb1b | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 27.011 |
| Running on/with | Platform Versions |
|---|---|
Rockwellautomation Compactlogix 1769 L24er Qb1b | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 27.011 |
| Running on/with | Platform Versions |
|---|---|
Rockwellautomation Compactlogix 1769 L24er Qbfc1b | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 27.011 |
| Running on/with | Platform Versions |
|---|---|
Rockwellautomation Compactlogix 1769 L27erm Qbfc1b | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 27.011 |
| Running on/with | Platform Versions |
|---|---|
Rockwellautomation Compactlogix 1769 L30er | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 27.011 |
| Running on/with | Platform Versions |
|---|---|
Rockwellautomation Compactlogix 1769 L30erm | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 27.011 |
| Running on/with | Platform Versions |
|---|---|
Rockwellautomation Compactlogix 1769 L30er Nse | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 27.011 |
| Running on/with | Platform Versions |
|---|---|
Rockwellautomation Compactlogix 1769 L33er | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 27.011 |
| Running on/with | Platform Versions |
|---|---|
Rockwellautomation Compactlogix 1769 L33erm | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 27.011 |
| Running on/with | Platform Versions |
|---|---|
Rockwellautomation Compactlogix 1769 L36erm | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 20.018 |
| Running on/with | Platform Versions |
|---|---|
Rockwellautomation Compactlogix 1769 L23e Qb1b | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 20.018 |
| Running on/with | Platform Versions |
|---|---|
Rockwellautomation Compactlogix 1769 L23e Qbfc1b | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Rockwellautomation Compactlogix 1756 En2f Series A | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Rockwellautomation Compactlogix 1756 En2f Series B | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Rockwellautomation Compactlogix 1756 En2t Series A | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Rockwellautomation Compactlogix 1756 En2t Series B | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Rockwellautomation Compactlogix 1756 En2t Series C | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 10.007 |
| Running on/with | Platform Versions |
|---|---|
Rockwellautomation Compactlogix 1756 En2t Series D | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Rockwellautomation Compactlogix 1756 En2tr Series A | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Rockwellautomation Compactlogix 1756 En2tr Series B | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Rockwellautomation Compactlogix 1756 En3tr Series A | All versions |
References (6)
Source: ics-cert@hq.dhs.gov
Broken LinkThird Party AdvisoryVDB Entry
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: ics-cert@hq.dhs.gov
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Timeline
No history available yet.