ID

VAR-201508-0629


TITLE

Rockwell Automation 1766-L32 Series Remote File Contains Vulnerabilities

Trust: 0.6

sources: CNVD: CNVD-2015-05660

DESCRIPTION

The Rockwell Automation 1766-L32 Series is a 1766-L32 Series Programmable Logic Controller (PLC). The Rockwell Automation 1766-L32 Series failed to adequately filter user-submitted input, allowing remote attackers to exploit vulnerabilities to submit special requests to view system file content with WEB privileges

Trust: 0.72

sources: CNVD: CNVD-2015-05660 // IVD: 5b303fc4-1e6a-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS', 'Network device']sub_category: -

Trust: 0.6

category:['ICS']sub_category: -

Trust: 0.2

sources: IVD: 5b303fc4-1e6a-11e6-abef-000c29c66e3d // CNVD: CNVD-2015-05660

AFFECTED PRODUCTS

vendor:rockwellmodel:automation 1766-l32 seriesscope: - version: -

Trust: 0.6

vendor:rockwellmodel:automation 1766-l32 seriesscope:eqversion:*

Trust: 0.2

sources: IVD: 5b303fc4-1e6a-11e6-abef-000c29c66e3d // CNVD: CNVD-2015-05660

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2015-05660
value: MEDIUM

Trust: 0.6

IVD: 5b303fc4-1e6a-11e6-abef-000c29c66e3d
value: MEDIUM

Trust: 0.2

CNVD: CNVD-2015-05660
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: 5b303fc4-1e6a-11e6-abef-000c29c66e3d
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: 5b303fc4-1e6a-11e6-abef-000c29c66e3d // CNVD: CNVD-2015-05660

TYPE

Input validation

Trust: 0.2

sources: IVD: 5b303fc4-1e6a-11e6-abef-000c29c66e3d

PATCH

title:Rockwell Automation 1766-L32 Series remote file contains vulnerable patchesurl:https://www.cnvd.org.cn/patchinfo/show/63201

Trust: 0.6

sources: CNVD: CNVD-2015-05660

EXTERNAL IDS

db:CNVDid:CNVD-2015-05660

Trust: 0.8

db:IVDid:5B303FC4-1E6A-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: 5b303fc4-1e6a-11e6-abef-000c29c66e3d // CNVD: CNVD-2015-05660

REFERENCES

url:https://rockwellautomation.custhelp.com/app/answers/detail/a_id/54102

Trust: 0.6

sources: CNVD: CNVD-2015-05660

SOURCES

db:IVDid:5b303fc4-1e6a-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2015-05660

LAST UPDATE DATE

2022-05-17T01:47:57.120000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-05660date:2015-08-27T00:00:00

SOURCES RELEASE DATE

db:IVDid:5b303fc4-1e6a-11e6-abef-000c29c66e3ddate:2015-08-27T00:00:00
db:CNVDid:CNVD-2015-05660date:2015-08-27T00:00:00