Record summary

CVE-2017-7924 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.

Description

An Improper Input Validation issue was discovered in Rockwell Automation MicroLogix 1100 controllers 1763-L16BWA, 1763-L16AWA, 1763-L16BBB, and 1763-L16DWD. A remote, unauthenticated attacker could send a single, specially crafted Programmable Controller Communication Commands (PCCC) packet to the controller that could potentially cause the controller to enter a DoS condition.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Rockwell Automation MicroLogix 1100 Controllers

CVE ListRockwell Automation MicroLogix 1100 Controllersaffected

Proofs of concept

1

Catalogued exploits

MetasploitDoS Exploitation of Allen-Bradley's Legacy Protocol (PCCC)Metasploit auxiliary PoCby José Diogo Monteiro <jdlopes@student.dei.uc.pt> +2 moreNot analyzed1 file

Ruby

Metasploit

PoC details

References

3