CVE-2016-9343
An issue was discovered in Rockwell Automation Logix5000 Programmable Automation Controller FRN 16.00 through 21.00 (excluding all firmware versions prior to FRN 16.00, which are not affected). By ...
Affects 32 products across 1 vendor.
Software writes data past buffer boundaries, corrupting memory and potentially enabling code execution.
A critical vulnerability exists in Rockwell Automation Logix5000 PACs (FRN 16.00 - 21.00) where a malformed CIP packet can lead to a stack-based buffer overflow, potentially allowing remote code execution or a non-recoverable denial of service.
BSID: BS-2017-GLOBAL-342586-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2016-9343?
What is the CVSS score for CVE-2016-9343?
Is CVE-2016-9343 actively exploited?
How do I remediate CVE-2016-9343?
What systems are affected by CVE-2016-9343?
What NERC-CIP standard applies to CVE-2016-9343?
What IEC 62443 requirement maps to CVE-2016-9343?
| CVE ID | CVE-2016-9343 |
|---|---|
| BSID | BS-2017-GLOBAL-342586-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Published | 2017-02-13 |
| Last Modified | 2026-05-13 |
| ICS Relevance | 100% |
| Weakness (CWE) | |
| Verticals | |
| Source | NVD |
An issue was discovered in Rockwell Automation Logix5000 Programmable Automation Controller FRN 16.00 through 21.00 (excluding all firmware versions prior to FRN 16.00, which are not affected). By sending malformed common industrial protocol (CIP) packet, an attacker may be able to overflow a stack-based buffer and execute code on the controller or initiate a nonrecoverable fault resulting in a denial of service.
Source: NIST NVD / MITRE CVE Database
The vulnerability can be exploited by sending a specially crafted CIP packet over the network to the affected Logix5000 PAC. This can result in a stack-based buffer overflow, leading to arbitrary code execution or a non-recoverable fault that causes a denial of service.
Exploitation Likelihood: MEDIUM
| Vendor | Product | Fixed Version |
|---|---|---|
| Rockwell Automation | Softlogix 5800 Controller Firmware | — |
| Rockwell Automation | Softlogix 5800 Controller | — |
| Rockwell Automation | Rslogix Emulate 5000 Firmware | — |
| Rockwell Automation | Rslogix Emulate 5000 | — |
| Rockwell Automation | Guardlogix 5570 Controller Firmware | — |
| Rockwell Automation | Guardlogix 5570 Controller | — |
| Rockwell Automation | Flexlogix L34 Controller Firmware | — |
| Rockwell Automation | Flexlogix L34 Controller | — |
| Rockwell Automation | Controllogix L55 Controller Firmware | — |
| Rockwell Automation | Controllogix L55 Controller | — |
| Rockwell Automation | Controllogix 5570 Redundant Controller Firmware | — |
| Rockwell Automation | Controllogix 5570 Redundant Controller | — |
| Rockwell Automation | Controllogix 5570 Controller Firmware | — |
| Rockwell Automation | Controllogix 5570 Controller | — |
| Rockwell Automation | Controllogix 5560 Redundant Controller Firmware | — |
| Rockwell Automation | Controllogix 5560 Redundant Controller | — |
| Rockwell Automation | Controllogix 5560 Controller Firmware | — |
| Rockwell Automation | Controllogix 5560 Controller | — |
| Rockwell Automation | 1769 Compactlogix L3X Controller Firmware | — |
| Rockwell Automation | 1769 Compactlogix L3X Controller | — |
| Rockwell Automation | 1769 Compactlogix L23X Controller Firmware | — |
| Rockwell Automation | 1769 Compactlogix L23X Controller | — |
| Rockwell Automation | 1769 Compactlogix 5370 L3 Controller Firmware | — |
| Rockwell Automation | 1769 Compactlogix 5370 L3 Controller | — |
| Rockwell Automation | 1769 Compactlogix 5370 L2 Controller Firmware | — |
| Rockwell Automation | 1769 Compactlogix 5370 L2 Controller | — |
| Rockwell Automation | 1769 Compactlogix 5370 L1 Controller Firmware | — |
| Rockwell Automation | 1769 Compactlogix 5370 L1 Controller | — |
| Rockwell Automation | 1768 Compactlogix L4X Controller Firmware | — |
| Rockwell Automation | 1768 Compactlogix L4X Controller | — |
| Rockwell Automation | 1768 Compact Guardlogix L4Xs Controller Firmware | — |
| Rockwell Automation | 1768 Compact Guardlogix L4Xs Controller | — |
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Implement network segmentation and access controls to restrict communication to the affected PACs only from trusted sources. Use deep packet inspection to monitor and block suspicious CIP traffic.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.
This CVE violates CIP-007-R2 as it allows unauthorized access to the control system, which could compromise the integrity and availability of the system.
This CVE maps to SR 7.6 because it involves a vulnerability that can be exploited remotely, leading to a loss of control system integrity and availability.
Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.
SAGE Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | e448796055ae1c571160511091ac4dc389ef57aa5fbd27681e8c07cfc2ec967fd67d7fbdc3365173965f88c5053c732aaa3e1c1d8aa4438138115758cae56cc1 |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →