CVE-2017-7898

CRITICAL

Rockwellautomation 1763-l16awa Series A < 16.000 - Brute Force

Title source: rule
STIX 2.1

Description

An Improper Restriction of Excessive Authentication Attempts issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prior versions; 1763-L16BBB, Series A and B, Version 16.00 and prior versions; 1763-L16BWA, Series A and B, Version 16.00 and prior versions; and 1763-L16DWD, Series A and B, Version 16.00 and prior versions and Allen-Bradley MicroLogix 1400 programmable logic controllers 1766-L32AWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWAA, Series A and B, Version 16.00 and prior versions; 1766-L32BXB, Series A and B, Version 16.00 and prior versions; 1766-L32BXBA, Series A and B, Version 16.00 and prior versions; and 1766-L32AWAA, Series A and B, Version 16.00 and prior versions. There are no penalties for repeatedly entering incorrect passwords.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1038546
Patch, Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-17-115-04

Scores

CVSS v3 9.8
EPSS 0.0114
EPSS Percentile 78.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-307
Status published
Products (21)
n/a/Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400
rockwellautomation/1763-l16awa_series_a < 16.000
rockwellautomation/1763-l16awa_series_b < 16.000
rockwellautomation/1763-l16bbb_series_a < 16.000
rockwellautomation/1763-l16bbb_series_b < 16.000
rockwellautomation/1763-l16bwa_series_a < 16.000
rockwellautomation/1763-l16bwa_series_b < 16.000
rockwellautomation/1763-l16dwd_series_a < 16.000
rockwellautomation/1763-l16dwd_series_b < 16.000
rockwellautomation/1766-l32awa_series_a < 16.000
... and 11 more
Published Jun 30, 2017
Tracked Since Feb 18, 2026