Lucene search

K
cvelistIcscertCVELIST:CVE-2017-7902
HistoryJun 30, 2017 - 2:35 a.m.

CVE-2017-7902

2017-06-3002:35:00
CWE-323
icscert
www.cve.org
7

AI Score

9.3

Confidence

High

EPSS

0.001

Percentile

34.8%

A “Reusing a Nonce, Key Pair in Encryption” issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prior versions; 1763-L16BBB, Series A and B, Version 16.00 and prior versions; 1763-L16BWA, Series A and B, Version 16.00 and prior versions; and 1763-L16DWD, Series A and B, Version 16.00 and prior versions and Allen-Bradley MicroLogix 1400 programmable logic controllers 1766-L32AWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWAA, Series A and B, Version 16.00 and prior versions; 1766-L32BXB, Series A and B, Version 16.00 and prior versions; 1766-L32BXBA, Series A and B, Version 16.00 and prior versions; and 1766-L32AWAA, Series A and B, Version 16.00 and prior versions. The affected product reuses nonces, which may allow an attacker to capture and replay a valid request until the nonce is changed.

CNA Affected

[
  {
    "product": "Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400"
      }
    ]
  }
]

AI Score

9.3

Confidence

High

EPSS

0.001

Percentile

34.8%

Related for CVELIST:CVE-2017-7902