CVE-2016-9343 Vulnerability Details

  /     /     /  

CVE-2016-9343 Metadata Quick Info

CVE Published: 13/02/2017 | CVE Updated: 06/08/2024 | CVE Year: 2016
Source: icscert | Vendor: n/a | Product: Rockwell Automation Logix5000 Programmable Automation Controller FRN 16.00 through 21.00
Status : PUBLISHED

CVE-2016-9343 Description

An issue was discovered in Rockwell Automation Logix5000 Programmable Automation Controller FRN 16.00 through 21.00 (excluding all firmware versions prior to FRN 16.00, which are not affected). By sending malformed common industrial protocol (CIP) packet, an attacker may be able to overflow a stack-based buffer and execute code on the controller or initiate a nonrecoverable fault resulting in a denial of service.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Rockwell Automation Logix5000 Programmable Automation Controller Buffer Overflow Vulnerability
Source: n/a

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).