CVSS v3
9.8
CRITICAL
EPSS Score
37.0 %
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings, or modification of ladder logic. An attacker can send unauthenticated packets to trigger this vulnerability.Required Keyswitch State: REMOTE or PROG Associated Fault Code: 0001 Fault Type: Non-User Description: A fault state can be triggered by setting the NVRAM/memory module user program mismatch bit (S2:9) when a memory module is NOT installed.
Technical details
- Published
- 2018-04-05
Frequently asked questions
What is CVE-2017-14464?
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings, or modification of ladder logic. An attacker can send unauthenticated packets to trigger this vulnerability.Required Keyswitch State: REMOTE or PROG Associated Fault Code: 0001 Fault Type: Non-User Description: A fault state can be triggered by setting the NVRAM/memory module user program mismatch bit (S2:9) when a memory module is NOT installed.
Is CVE-2017-14464 actively exploited?
Active exploitation of CVE-2017-14464 has not been confirmed. The EPSS score is 37.0%, indicating the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2017-14464?
CVE-2017-14464 has a CVSS v3 base score of 9.8 (CRITICAL severity).
Is CVE-2017-14464 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2017 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).