CVE Vulnerabilities

CVE-2017-7914

Published: Jun 14, 2017 | Modified: Nov 21, 2024
CVSS 3.x
8.6
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

A Missing Authorization issue was discovered in Rockwell Automation PanelView Plus 6 700-1500 6.00.04, 6.00.05, 6.00.42, 6.00-20140306, 6.10.20121012, 6.10-20140122, 7.00-20121012, 7.00-20130108, 7.00-20130325, 7.00-20130619, 7.00-20140128, 7.00-20140310, 7.00-20140429, 7.00-20140621, 7.00-20140729, 7.00-20141022, 8.00-20140730, and 8.00-20141023. There is no authorization check when connecting to the device, allowing an attacker remote access.

Affected Software

Name Vendor Start Version End Version
Panelview_plus_6_700-1500_firmware Rockwellautomation 6.00-20140306 (including) 6.00-20140306 (including)
Panelview_plus_6_700-1500_firmware Rockwellautomation 6.00.04 (including) 6.00.04 (including)
Panelview_plus_6_700-1500_firmware Rockwellautomation 6.00.05 (including) 6.00.05 (including)
Panelview_plus_6_700-1500_firmware Rockwellautomation 6.00.42 (including) 6.00.42 (including)
Panelview_plus_6_700-1500_firmware Rockwellautomation 6.10-20140122 (including) 6.10-20140122 (including)
Panelview_plus_6_700-1500_firmware Rockwellautomation 6.10.20121012 (including) 6.10.20121012 (including)
Panelview_plus_6_700-1500_firmware Rockwellautomation 7.00-20121012 (including) 7.00-20121012 (including)
Panelview_plus_6_700-1500_firmware Rockwellautomation 7.00-20130108 (including) 7.00-20130108 (including)
Panelview_plus_6_700-1500_firmware Rockwellautomation 7.00-20130325 (including) 7.00-20130325 (including)
Panelview_plus_6_700-1500_firmware Rockwellautomation 7.00-20130619 (including) 7.00-20130619 (including)
Panelview_plus_6_700-1500_firmware Rockwellautomation 7.00-20140128 (including) 7.00-20140128 (including)
Panelview_plus_6_700-1500_firmware Rockwellautomation 7.00-20140310 (including) 7.00-20140310 (including)
Panelview_plus_6_700-1500_firmware Rockwellautomation 7.00-20140429 (including) 7.00-20140429 (including)
Panelview_plus_6_700-1500_firmware Rockwellautomation 7.00-20140621 (including) 7.00-20140621 (including)
Panelview_plus_6_700-1500_firmware Rockwellautomation 7.00-20140729 (including) 7.00-20140729 (including)
Panelview_plus_6_700-1500_firmware Rockwellautomation 7.00-20141022 (including) 7.00-20141022 (including)
Panelview_plus_6_700-1500_firmware Rockwellautomation 8.00-20140730 (including) 8.00-20140730 (including)
Panelview_plus_6_700-1500_firmware Rockwellautomation 8.00-20141023 (including) 8.00-20141023 (including)

References