HIGH · 7.3

CVE-2016-5645

Rockwell Automation MicroLogix 1400 PLC 1766-L32BWA, 1766-L32AWA, 1766-L32BXB, 1766-L32BWAA, 1766-L32AWAA, and 1766-L32BXBA devices have a hardcoded SNMP community, which makes it easier for remote at...

Vulnerability Description

Rockwell Automation MicroLogix 1400 PLC 1766-L32BWA, 1766-L32AWA, 1766-L32BXB, 1766-L32BWAA, 1766-L32AWAA, and 1766-L32BXBA devices have a hardcoded SNMP community, which makes it easier for remote attackers to load arbitrary firmware updates by leveraging knowledge of this community.

CVSS Score

7.3

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
Rockwellautomation1766-L32Awa-
Rockwellautomation1766-L32Awaa-
Rockwellautomation1766-L32Bwa-
Rockwellautomation1766-L32Bwaa-
Rockwellautomation1766-L32Bxb-
Rockwellautomation1766-L32Bxba-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-5645?

CVE-2016-5645 is a vulnerability with a CVSS score of 7.3 (HIGH). Rockwell Automation MicroLogix 1400 PLC 1766-L32BWA, 1766-L32AWA, 1766-L32BXB, 1766-L32BWAA, 1766-L32AWAA, and 1766-L32BXBA devices have a hardcoded SNMP community, which makes it easier for remote at...

How severe is CVE-2016-5645?

CVE-2016-5645 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-5645?

Check the references section above for vendor advisories and patch information. Affected products include: Rockwellautomation 1766-L32Awa, Rockwellautomation 1766-L32Awaa, Rockwellautomation 1766-L32Bwa, Rockwellautomation 1766-L32Bwaa, Rockwellautomation 1766-L32Bxb.