CRITICAL · 10.0

CVE-2016-9343

An issue was discovered in Rockwell Automation Logix5000 Programmable Automation Controller FRN 16.00 through 21.00 (excluding all firmware versions prior to FRN 16.00, which are not affected). By sen...

Vulnerability Description

An issue was discovered in Rockwell Automation Logix5000 Programmable Automation Controller FRN 16.00 through 21.00 (excluding all firmware versions prior to FRN 16.00, which are not affected). By sending malformed common industrial protocol (CIP) packet, an attacker may be able to overflow a stack-based buffer and execute code on the controller or initiate a nonrecoverable fault resulting in a denial of service.

CVSS Score

10.0

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
RockwellautomationSoftlogix 5800 Controller Firmware18.00
RockwellautomationSoftlogix 5800 Controller-
RockwellautomationRslogix Emulate 5000 Firmware18.00
RockwellautomationRslogix Emulate 5000-
RockwellautomationGuardlogix 5570 Controller Firmware16.00
RockwellautomationGuardlogix 5570 Controller-
RockwellautomationFlexlogix L34 Controller Firmware16.00
RockwellautomationFlexlogix L34 Controller-
RockwellautomationControllogix L55 Controller Firmware16.00
RockwellautomationControllogix L55 Controller-
RockwellautomationControllogix 5570 Redundant Controller Firmware20.00
RockwellautomationControllogix 5570 Redundant Controller-
RockwellautomationControllogix 5570 Controller Firmware18.00
RockwellautomationControllogix 5570 Controller-
RockwellautomationControllogix 5560 Redundant Controller Firmware16.00
RockwellautomationControllogix 5560 Redundant Controller-
RockwellautomationControllogix 5560 Controller Firmware16.00
RockwellautomationControllogix 5560 Controller-
Rockwellautomation1769 Compactlogix L3X Controller Firmware16.00
Rockwellautomation1769 Compactlogix L3X Controller-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-9343?

CVE-2016-9343 is a vulnerability with a CVSS score of 10.0 (CRITICAL). An issue was discovered in Rockwell Automation Logix5000 Programmable Automation Controller FRN 16.00 through 21.00 (excluding all firmware versions prior to FRN 16.00, which are not affected). By sen...

How severe is CVE-2016-9343?

CVE-2016-9343 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2016-9343?

Check the references section above for vendor advisories and patch information. Affected products include: Rockwellautomation Softlogix 5800 Controller Firmware, Rockwellautomation Softlogix 5800 Controller, Rockwellautomation Rslogix Emulate 5000 Firmware, Rockwellautomation Rslogix Emulate 5000, Rockwellautomation Guardlogix 5570 Controller Firmware.