Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-7899


An Information Exposure issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prior versions; 1763-L16BBB, Series A and B, Version 16.00 and prior versions; 1763-L16BWA, Series A and B, Version 16.00 and prior versions; and 1763-L16DWD, Series A and B, Version 16.00 and prior versions and Allen-Bradley MicroLogix 1400 programmable logic controllers 1766-L32AWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWAA, Series A and B, Version 16.00 and prior versions; 1766-L32BXB, Series A and B, Version 16.00 and prior versions; 1766-L32BXBA, Series A and B, Version 16.00 and prior versions; and 1766-L32AWAA, Series A and B, Version 16.00 and prior versions. User credentials are sent to the web server using the HTTP GET method, which may result in the credentials being logged. This could make user credentials available for unauthorized retrieval.


Published

2017-06-30T03:29:00.733

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-200
  • Type: Primary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application rockwellautomation 1763-l16awa_series_a ≤ 16.000 Yes
Application rockwellautomation 1763-l16awa_series_b ≤ 16.000 Yes
Application rockwellautomation 1763-l16bbb_series_a ≤ 16.000 Yes
Application rockwellautomation 1763-l16bbb_series_b ≤ 16.000 Yes
Application rockwellautomation 1763-l16bwa_series_a ≤ 16.000 Yes
Application rockwellautomation 1763-l16bwa_series_b ≤ 16.000 Yes
Application rockwellautomation 1763-l16dwd_series_a ≤ 16.000 Yes
Application rockwellautomation 1763-l16dwd_series_b ≤ 16.000 Yes
Hardware rockwellautomation ab_micrologix_controller 1100 No
Application rockwellautomation 1766-l32awa_series_a ≤ 16.000 Yes
Application rockwellautomation 1766-l32awa_series_b ≤ 16.000 Yes
Application rockwellautomation 1766-l32awaa_series_a ≤ 16.000 Yes
Application rockwellautomation 1766-l32awaa_series_b ≤ 16.000 Yes
Application rockwellautomation 1766-l32bwa_series_a ≤ 16.000 Yes
Application rockwellautomation 1766-l32bwa_series_b ≤ 16.000 Yes
Application rockwellautomation 1766-l32bwaa_series_a ≤ 16.000 Yes
Application rockwellautomation 1766-l32bwaa_series_b ≤ 16.000 Yes
Application rockwellautomation 1766-l32bxb_series_a ≤ 16.000 Yes
Application rockwellautomation 1766-l32bxb_series_b ≤ 16.000 Yes
Application rockwellautomation 1766-l32bxba_series_a ≤ 16.000 Yes
Application rockwellautomation 1766-l32bxba_series_b ≤ 16.000 Yes
Hardware rockwellautomation ab_micrologix_controller 1400 No

References