Description
An issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 controller 1763-L16AWA, Series A and B, Version 14.000 and prior versions; 1763-L16BBB, Series A and B, Version 14.000 and prior versions; 1763-L16BWA, Series A and B, Version 14.000 and prior versions; and 1763-L16DWD, Series A and B, Version 14.000 and prior versions. Because of an Incorrect Permission Assignment for Critical Resource, users with administrator privileges may be able to remove all administrative users requiring a factory reset to restore ancillary web server function. Exploitation of this vulnerability will still allow the affected device to function in its capacity as a controller.
Published: 2017-02-13
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2016-10148 An issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 controller 1763-L16AWA, Series A and B, Version 14.000 and prior versions; 1763-L16BBB, Series A and B, Version 14.000 and prior versions; 1763-L16BWA, Series A and B, Version 14.000 and prior versions; and 1763-L16DWD, Series A and B, Version 14.000 and prior versions. Because of an Incorrect Permission Assignment for Critical Resource, users with administrator privileges may be able to remove all administrative users requiring a factory reset to restore ancillary web server function. Exploitation of this vulnerability will still allow the affected device to function in its capacity as a controller.
History

No history.

Subscriptions

Rockwellautomation 1763-l16awa Series A 1763-l16awa Series B 1763-l16bbb Series A 1763-l16bbb Series B 1763-l16bwa Series A 1763-l16bwa Series B 1763-l16dwd Series A 1763-l16dwd Series B 1766-l32awa Series A 1766-l32awa Series B 1766-l32awaa Series A 1766-l32awaa Series B 1766-l32bwa Series A 1766-l32bwa Series B 1766-l32bwaa Series A 1766-l32bwaa Series B 1766-l32bxb Series A 1766-l32bxb Series B 1766-l32bxba Series A 1766-l32bxba Series B
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-06T02:50:36.961Z

Reserved: 2016-11-16T00:00:00.000Z

Link: CVE-2016-9338

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2017-02-13T21:59:01.627

Modified: 2026-05-13T00:24:29.033

Link: CVE-2016-9338

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses