CVE-2016-9343

CRITICAL

An issue was discovered in Rockwell Automation Logix5000 Programmable Automation Controller FRN 16.00 through 21.00 (excluding all firmware versions prior to FRN 16.00, which are not affected). By ...

Affects 32 products across 1 vendor.

BCS7.0
CVSS 3.110.0
EPSS10.5%
Percentile95th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-787: Out-of-Bounds Write

Software writes data past buffer boundaries, corrupting memory and potentially enabling code execution.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical vulnerability exists in Rockwell Automation Logix5000 PACs (FRN 16.00 - 21.00) where a malformed CIP packet can lead to a stack-based buffer overflow, potentially allowing remote code execution or a non-recoverable denial of service.

BSID: BS-2017-GLOBAL-342586-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2016-9343?
A critical vulnerability exists in Rockwell Automation Logix5000 PACs (FRN 16.00 - 21.00) where a malformed CIP packet can lead to a stack-based buffer overflow, potentially allowing remote code execution or a non-recoverable denial of service.
What is the CVSS score for CVE-2016-9343?
CVE-2016-9343 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 10.5%.
Is CVE-2016-9343 actively exploited?
No confirmed active exploitation of CVE-2016-9343 as of 2026-05-30.
How do I remediate CVE-2016-9343?
Priority: IMMEDIATE. Advisory: https://ics-cert.us-cert.gov/advisories/ICSA-16-343-05
What systems are affected by CVE-2016-9343?
CVE-2016-9343 affects: Rockwell Automation, Rockwell Automation, Rockwell Automation, Rockwell Automation, Rockwell Automation, Rockwell Automation, Rockwell Automation, Rockwell Automation.
What NERC-CIP standard applies to CVE-2016-9343?
NERC CIP CIP-007 CIP-007-R2: This CVE violates CIP-007-R2 as it allows unauthorized access to the control system, which could compromise the integrity and availability of the system.
What IEC 62443 requirement maps to CVE-2016-9343?
IEC 62443 SR 7.6: This CVE maps to SR 7.6 because it involves a vulnerability that can be exploited remotely, leading to a loss of control system integrity and availability.
Vulnerability Details
CVE IDCVE-2016-9343
BSIDBS-2017-GLOBAL-342586-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2017-02-13
Last Modified2026-05-13
ICS Relevance100%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

An issue was discovered in Rockwell Automation Logix5000 Programmable Automation Controller FRN 16.00 through 21.00 (excluding all firmware versions prior to FRN 16.00, which are not affected). By sending malformed common industrial protocol (CIP) packet, an attacker may be able to overflow a stack-based buffer and execute code on the controller or initiate a nonrecoverable fault resulting in a denial of service.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability can be exploited by sending a specially crafted CIP packet over the network to the affected Logix5000 PAC. This can result in a stack-based buffer overflow, leading to arbitrary code execution or a non-recoverable fault that causes a denial of service.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Rockwell Automation Softlogix 5800 Controller Firmware
Rockwell Automation Softlogix 5800 Controller
Rockwell Automation Rslogix Emulate 5000 Firmware
Rockwell Automation Rslogix Emulate 5000
Rockwell Automation Guardlogix 5570 Controller Firmware
Rockwell Automation Guardlogix 5570 Controller
Rockwell Automation Flexlogix L34 Controller Firmware
Rockwell Automation Flexlogix L34 Controller
Rockwell Automation Controllogix L55 Controller Firmware
Rockwell Automation Controllogix L55 Controller
Rockwell Automation Controllogix 5570 Redundant Controller Firmware
Rockwell Automation Controllogix 5570 Redundant Controller
Rockwell Automation Controllogix 5570 Controller Firmware
Rockwell Automation Controllogix 5570 Controller
Rockwell Automation Controllogix 5560 Redundant Controller Firmware
Rockwell Automation Controllogix 5560 Redundant Controller
Rockwell Automation Controllogix 5560 Controller Firmware
Rockwell Automation Controllogix 5560 Controller
Rockwell Automation 1769 Compactlogix L3X Controller Firmware
Rockwell Automation 1769 Compactlogix L3X Controller
Rockwell Automation 1769 Compactlogix L23X Controller Firmware
Rockwell Automation 1769 Compactlogix L23X Controller
Rockwell Automation 1769 Compactlogix 5370 L3 Controller Firmware
Rockwell Automation 1769 Compactlogix 5370 L3 Controller
Rockwell Automation 1769 Compactlogix 5370 L2 Controller Firmware
Rockwell Automation 1769 Compactlogix 5370 L2 Controller
Rockwell Automation 1769 Compactlogix 5370 L1 Controller Firmware
Rockwell Automation 1769 Compactlogix 5370 L1 Controller
Rockwell Automation 1768 Compactlogix L4X Controller Firmware
Rockwell Automation 1768 Compactlogix L4X Controller
Rockwell Automation 1768 Compact Guardlogix L4Xs Controller Firmware
Rockwell Automation 1768 Compact Guardlogix L4Xs Controller
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 3459 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement network segmentation and access controls to restrict communication to the affected PACs only from trusted sources. Use deep packet inspection to monitor and block suspicious CIP traffic.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R2
This CVE violates CIP-007-R2 as it allows unauthorized access to the control system, which could compromise the integrity and availability of the system.
IEC 62443: SR 7.6
This CVE maps to SR 7.6 because it involves a vulnerability that can be exploited remotely, leading to a loss of control system integrity and availability.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashe448796055ae1c571160511091ac4dc389ef57aa5fbd27681e8c07cfc2ec967fd67d7fbdc3365173965f88c5053c732aaa3e1c1d8aa4438138115758cae56cc1
Related CVEs affecting Rockwell Automation
CVE-2020-14516 10.0 In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.1... CVE-2012-4715 10.0 Buffer overflow in LogReceiver.exe in Rockwell Automation RSLinx Enterprise C... CVE-2009-3739 10.0 Multiple unspecified vulnerabilities on the Rockwell Automation AB Micrologix... CVE-2017-16740 10.0 A Buffer Overflow issue was discovered in Rockwell Automation Allen-Bradley M... CVE-2023-20198 10.0 Cisco is providing an update for the ongoing investigation into observed expl...
View all Rockwell Automation CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →