7.5
CVE-2016-5645
- EPSS 30.31%
- Published 24.08.2016 02:00:12
- Last modified 12.04.2025 10:46:40
- Source cret@cert.org
- Teams watchlist Login
- Open Login
Rockwell Automation MicroLogix 1400 PLC 1766-L32BWA, 1766-L32AWA, 1766-L32BXB, 1766-L32BWAA, 1766-L32AWAA, and 1766-L32BXBA devices have a hardcoded SNMP community, which makes it easier for remote attackers to load arbitrary firmware updates by leveraging knowledge of this community.
Data is provided by the National Vulnerability Database (NVD)
Rockwellautomation ≫ 1766-l32awa Version-
Rockwellautomation ≫ 1766-l32awaa Version-
Rockwellautomation ≫ 1766-l32bwa Version-
Rockwellautomation ≫ 1766-l32bwaa Version-
Rockwellautomation ≫ 1766-l32bxb Version-
Rockwellautomation ≫ 1766-l32bxba Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 30.31% | 0.964 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.3 | 3.9 | 3.4 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
|
nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.