Lucene search

K
nvd[email protected]NVD:CVE-2016-5645
HistoryAug 24, 2016 - 2:00 a.m.

CVE-2016-5645

2016-08-2402:00:12
CWE-284
web.nvd.nist.gov
7

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

7.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

AI Score

7.2

Confidence

High

EPSS

0.135

Percentile

95.6%

Rockwell Automation MicroLogix 1400 PLC 1766-L32BWA, 1766-L32AWA, 1766-L32BXB, 1766-L32BWAA, 1766-L32AWAA, and 1766-L32BXBA devices have a hardcoded SNMP community, which makes it easier for remote attackers to load arbitrary firmware updates by leveraging knowledge of this community.

Affected configurations

Nvd
Node
rockwellautomation1766-l32awaMatch-
OR
rockwellautomation1766-l32awaaMatch-
OR
rockwellautomation1766-l32bwaMatch-
OR
rockwellautomation1766-l32bwaaMatch-
OR
rockwellautomation1766-l32bxbMatch-
OR
rockwellautomation1766-l32bxbaMatch-
VendorProductVersionCPE
rockwellautomation1766-l32awa-cpe:2.3:h:rockwellautomation:1766-l32awa:-:*:*:*:*:*:*:*
rockwellautomation1766-l32awaa-cpe:2.3:h:rockwellautomation:1766-l32awaa:-:*:*:*:*:*:*:*
rockwellautomation1766-l32bwa-cpe:2.3:h:rockwellautomation:1766-l32bwa:-:*:*:*:*:*:*:*
rockwellautomation1766-l32bwaa-cpe:2.3:h:rockwellautomation:1766-l32bwaa:-:*:*:*:*:*:*:*
rockwellautomation1766-l32bxb-cpe:2.3:h:rockwellautomation:1766-l32bxb:-:*:*:*:*:*:*:*
rockwellautomation1766-l32bxba-cpe:2.3:h:rockwellautomation:1766-l32bxba:-:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

7.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

AI Score

7.2

Confidence

High

EPSS

0.135

Percentile

95.6%