99622vdb entry
http://www.securityfocus.com/bid/99622 CVE-2017-7924
HIGH
DoS Exploitation of Allen-Bradley's Legacy Protocol (PCCC)
Record summary
CVE-2017-7924 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
An Improper Input Validation issue was discovered in Rockwell Automation MicroLogix 1100 controllers 1763-L16BWA, 1763-L16AWA, 1763-L16BBB, and 1763-L16DWD. A remote, unauthenticated attacker could send a single, specially crafted Programmable Controller Communication Commands (PCCC) packet to the controller that could potentially cause the controller to enter a DoS condition.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Rockwell Automation MicroLogix 1100 Controllers | CVE List | Rockwell Automation MicroLogix 1100 Controllers | affected |
Proofs of concept
1Catalogued exploits
MetasploitDoS Exploitation of Allen-Bradley's Legacy Protocol (PCCC)Metasploit auxiliary PoCby José Diogo Monteiro <jdlopes@student.dei.uc.pt> +2 moreNot analyzed1 file
References
3ics-cert.us-cert.gov
https://ics-cert.us-cert.gov/advisories/ICSA-17-138-03 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-7924