← Back

CVE-2016-9343

nvd nist
Published: Feb 13, 2017Modified: May 13, 2026

JSON object

Loading...
10.0
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 6.0
Source: NVD

Description

An issue was discovered in Rockwell Automation Logix5000 Programmable Automation Controller FRN 16.00 through 21.00 (excluding all firmware versions prior to FRN 16.00, which are not affected). By sending malformed common industrial protocol (CIP) packet, an attacker may be able to overflow a stack-based buffer and execute code on the controller or initiate a nonrecoverable fault resulting in a denial of service.

Affected (85)

Configuration A
4 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 18.00
Version 19.00
Version 20.00
Version 21.00
Running on/withPlatform Versions
Rockwellautomation
Softlogix 5800 Controller
All versions
Configuration B
4 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 18.00
Version 19.00
Version 20.00
Version 21.00
Running on/withPlatform Versions
Rockwellautomation
Rslogix Emulate 5000
All versions
Configuration C
8 vulnerable · 1 platform
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 16.00
Running on/withPlatform Versions
Rockwellautomation
Flexlogix L34 Controller
All versions
Configuration E
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 16.00
Version 16.020
Version 16.022
Running on/withPlatform Versions
Rockwellautomation
Controllogix L55 Controller
All versions
Configuration F
4 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 20.00
Version 20.050
Version 20.055
Version 21.00
Running on/withPlatform Versions
Rockwellautomation
Controllogix 5570 Redundant Controller
All versions
Configuration G
5 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 18.00
Version 19.00
Version 20.010
Version 20.013
Version 21.00
Running on/withPlatform Versions
Rockwellautomation
Controllogix 5570 Controller
All versions
Configuration H
5 vulnerable · 1 platform
Configuration I
9 vulnerable · 1 platform
Configuration J
9 vulnerable · 1 platform
Configuration K
7 vulnerable · 1 platform
Configuration L
4 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 20.00
Version 20.010
Version 20.013
Version 21.00
Running on/withPlatform Versions
Rockwellautomation
1769 Compactlogix 5370 L3 Controller
All versions
Configuration M
4 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 20.00
Version 20.010
Version 20.013
Version 21.00
Running on/withPlatform Versions
Rockwellautomation
1769 Compactlogix 5370 L2 Controller
All versions
Configuration N
4 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 20.00
Version 20.010
Version 20.013
Version 21.00
Running on/withPlatform Versions
Rockwellautomation
1769 Compactlogix 5370 L1 Controller
All versions
Configuration O
9 vulnerable · 1 platform
Configuration P
5 vulnerable · 1 platform

References (4)

Source: ics-cert@hq.dhs.gov
Third Party AdvisoryVDB Entry
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.