// For flags

CVE-2017-7914

 

Severity Score

8.6
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A Missing Authorization issue was discovered in Rockwell Automation PanelView Plus 6 700-1500 6.00.04, 6.00.05, 6.00.42, 6.00-20140306, 6.10.20121012, 6.10-20140122, 7.00-20121012, 7.00-20130108, 7.00-20130325, 7.00-20130619, 7.00-20140128, 7.00-20140310, 7.00-20140429, 7.00-20140621, 7.00-20140729, 7.00-20141022, 8.00-20140730, and 8.00-20141023. There is no authorization check when connecting to the device, allowing an attacker remote access.

Se ha descubierto un problema de falta de autorización en Rockwell Automation PanelView Plus 6 700-1500 6.00.04, 6.00.05, 6.00.42, 6.00-20140306, 6.10.20121012, 6.10-20140122, 7.00-20121012, 7.00-20130108, 7.00-20130325, 7.00-20130619, 7.00-20140128, 7.00-20140310, 7.00-20140429, 7.00-20140621, 7.00-20140729, 7.00-20141022, 8.00-20140730 y 8.00-20141023. No hay comprobación de autorización al conectarse al dispositivo, lo que permite que un atacante logre el acceso remoto.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2017-04-18 CVE Reserved
  • 2017-06-14 CVE Published
  • 2023-04-24 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-862: Missing Authorization
  • CWE-882: CERT C++ Secure Coding Section 14 - Concurrency (CON)
CAPEC
References (1)
URL Date SRC
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500 Firmware
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware"
6.00-20140306
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware" and version "6.00-20140306"
-
Affected
in Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500"
--
Safe
Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500 Firmware
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware"
6.00.04
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware" and version "6.00.04"
-
Affected
in Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500"
--
Safe
Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500 Firmware
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware"
6.00.05
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware" and version "6.00.05"
-
Affected
in Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500"
--
Safe
Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500 Firmware
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware"
6.00.42
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware" and version "6.00.42"
-
Affected
in Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500"
--
Safe
Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500 Firmware
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware"
6.10-20140122
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware" and version "6.10-20140122"
-
Affected
in Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500"
--
Safe
Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500 Firmware
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware"
6.10.20121012
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware" and version "6.10.20121012"
-
Affected
in Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500"
--
Safe
Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500 Firmware
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware"
7.00-20121012
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware" and version "7.00-20121012"
-
Affected
in Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500"
--
Safe
Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500 Firmware
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware"
7.00-20130108
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware" and version "7.00-20130108"
-
Affected
in Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500"
--
Safe
Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500 Firmware
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware"
7.00-20130325
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware" and version "7.00-20130325"
-
Affected
in Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500"
--
Safe
Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500 Firmware
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware"
7.00-20130619
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware" and version "7.00-20130619"
-
Affected
in Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500"
--
Safe
Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500 Firmware
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware"
7.00-20140128
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware" and version "7.00-20140128"
-
Affected
in Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500"
--
Safe
Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500 Firmware
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware"
7.00-20140310
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware" and version "7.00-20140310"
-
Affected
in Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500"
--
Safe
Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500 Firmware
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware"
7.00-20140429
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware" and version "7.00-20140429"
-
Affected
in Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500"
--
Safe
Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500 Firmware
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware"
7.00-20140621
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware" and version "7.00-20140621"
-
Affected
in Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500"
--
Safe
Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500 Firmware
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware"
7.00-20140729
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware" and version "7.00-20140729"
-
Affected
in Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500"
--
Safe
Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500 Firmware
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware"
7.00-20141022
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware" and version "7.00-20141022"
-
Affected
in Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500"
--
Safe
Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500 Firmware
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware"
8.00-20140730
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware" and version "8.00-20140730"
-
Affected
in Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500"
--
Safe
Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500 Firmware
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware"
8.00-20141023
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500 Firmware" and version "8.00-20141023"
-
Affected
in Rockwellautomation
Search vendor "Rockwellautomation"
Panelview Plus 6 700-1500
Search vendor "Rockwellautomation" for product "Panelview Plus 6 700-1500"
--
Safe