CVE-2016-9334

UnknownEPSS 4.03%

Last modified

CVE-2016-9334 is a vulnerability of currently unknown severity. An issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 controller 1763-L16AWA, Series A and B, Version 14.000 and prior versions; 1763-L16BBB, Series A and B, Version 14.000 and prior versions; 1763-L16BWA, Series A and B, Version 14.000 and prior versions; and 1763-L16DWD, Series A and B, Version 14.000 and prior versions. User credentials are sent to the web server in clear text, which may allow an attacker to discover the credentials if they are able to observe traffic between the web browser and the server.. EPSS estimates a 4.03% chance of exploitation in the next 30 days.

Description

An issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 controller 1763-L16AWA, Series A and B, Version 14.000 and prior versions; 1763-L16BBB, Series A and B, Version 14.000 and prior versions; 1763-L16BWA, Series A and B, Version 14.000 and prior versions; and 1763-L16DWD, Series A and B, Version 14.000 and prior versions. User credentials are sent to the web server in clear text, which may allow an attacker to discover the credentials if they are able to observe traffic between the web browser and the server.

Metrics

EPSS Probability
4.03%

89.3th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
Rockwellautomation1763-L16awa Series A<= 14.000
Rockwellautomation1763-L16awa Series B<= 14.000
Rockwellautomation1763-L16bbb Series A<= 14.000
Rockwellautomation1763-L16bbb Series B<= 14.000
Rockwellautomation1763-L16bwa Series A<= 14.000
Rockwellautomation1763-L16bwa Series B<= 14.000
Rockwellautomation1763-L16dwd Series A<= 14.000
Rockwellautomation1763-L16dwd Series B<= 14.000
Rockwellautomation1766-L32awa Series A<= 15.004
Rockwellautomation1766-L32awa Series B<= 15.004
Rockwellautomation1766-L32awaa Series A<= 15.004
Rockwellautomation1766-L32awaa Series B<= 15.004
Rockwellautomation1766-L32bwa Series A<= 15.004
Rockwellautomation1766-L32bwa Series B<= 15.004
Rockwellautomation1766-L32bwaa Series A<= 15.004
Rockwellautomation1766-L32bwaa Series B<= 15.004
Rockwellautomation1766-L32bxb Series A<= 15.004
Rockwellautomation1766-L32bxb Series B<= 15.004
Rockwellautomation1766-L32bxba Series A<= 15.004
Rockwellautomation1766-L32bxba Series B<= 15.004

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2016-9334?
An issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 controller 1763-L16AWA, Series A and B, Version 14.000 and prior versions; 1763-L16BBB, Series A and B, Version 14.000 and prior versions; 1763-L16BWA, Series A and B, Version 14.000 and prior versions; and 1763-L16DWD, Series A and B, Version 14.000 and prior versions. User credentials are sent to the web server in clear text, which may allow an attacker to discover the credentials if they are able to observe traffic between the web browser and the server.
How severe is CVE-2016-9334?
Severity scoring for CVE-2016-9334 is pending analysis. The EPSS model estimates a 4.03% probability of exploitation in the next 30 days.
How do I fix CVE-2016-9334?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2016-9334?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST