CVE-2016-9334 Information
Feb 14, 2021
cve
Description
An issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 controller 1763-L16AWA Series A and B Version 14.000 and prior versions; 1763-L16BBB Series A and B Version 14.000 and prior versions; 1763-L16BWA Series A and B Version 14.000 and prior versions; and 1763-L16DWD Series A and B Version 14.000 and prior versions. User credentials are sent to the web server in clear text which may allow an attacker to discover the credentials if they are able to observe traffic between the web browser and the server.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Reference
http://www.securityfocus.com/bid/95302 https://ics-cert.us-cert.gov/advisories/ICSA-16-336-06
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
LOW
Base Severity
7.3
Share on: