CVE-2016-5814 Information
Feb 14, 2021
cve
Description
Buffer overflow in Rockwell Automation RSLogix Micro Starter Lite RSLogix Micro Developer RSLogix 500 Starter Edition RSLogix 500 Standard Edition and RSLogix 500 Professional Edition allows remote attackers to execute arbitrary code via a crafted RSS project file.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Reference
http://www.securityfocus.com/bid/92983 https://ics-cert.us-cert.gov/advisories/ICSA-16-224-02
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.6
Share on: