CVE-2017-16740

CRITICAL

A Buffer Overflow issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1400 Controllers, Series B and C Versions 21.002 and earlier. The stack-based buffer overflow vulnerability ha...

Affects 12 products across 1 vendor.

BCS7.25
CVSS 3.010.0
EPSS7.1%
Percentile94th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-119: Improper Restriction of Operations within Memory Buffer

Parent class for buffer-related vulnerabilities where operations exceed buffer boundaries.

CWE-120: Buffer Copy without Checking Size (Classic Buffer Overflow)

Program copies data to a buffer without verifying the source data fits within the destination.

Related Attack Patterns (CAPEC)
CAPEC-8 Buffer Overflow in an API Call
via CWE-119 CWE-120
CAPEC-9 Buffer Overflow in Local Command-Line Utilities
via CWE-119 CWE-120
CAPEC-10 Buffer Overflow via Environment Variables
via CWE-119 CWE-120
CAPEC-14 Client-side Injection-induced Buffer Overflow
via CWE-119 CWE-120
CAPEC-24 Filter Failure through Buffer Overflow
via CWE-119 CWE-120
Show all 14

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical buffer overflow vulnerability exists in Rockwell Automation Allen-Bradley MicroLogix 1400 Controllers, Series B and C, versions 21.002 and earlier. This vulnerability could allow remote code execution, posing significant risks to operational safety and system integrity.

BSID: BS-2018-GLOBAL-227833-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2017-16740?
A critical buffer overflow vulnerability exists in Rockwell Automation Allen-Bradley MicroLogix 1400 Controllers, Series B and C, versions 21.002 and earlier. This vulnerability could allow remote code execution, posing significant risks to operational safety and system integrity.
What is the CVSS score for CVE-2017-16740?
CVE-2017-16740 has CVSS 10.0 (Critical). Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 7.1%.
Is CVE-2017-16740 actively exploited?
No confirmed active exploitation of CVE-2017-16740 as of 2026-05-30.
How do I remediate CVE-2017-16740?
Priority: HIGH. Advisory: https://ics-cert.us-cert.gov/advisories/ICSA-18-009-01
What systems are affected by CVE-2017-16740?
CVE-2017-16740 affects: Rockwell Automation, Rockwell Automation, Rockwell Automation, Rockwell Automation, Rockwell Automation, Rockwell Automation, Rockwell Automation, Rockwell Automation.
What NERC-CIP standard applies to CVE-2017-16740?
NERC CIP CIP-007 CIP-007-R2: This CVE violates CIP-007-R2 as it allows unauthorized access to control systems, which could compromise the reliability of the bulk electric system.
What IEC 62443 requirement maps to CVE-2017-16740?
IEC 62443 IEC 62443-3-3: This CVE maps to IEC 62443-3-3 because it involves a vulnerability that could lead to remote code execution, compromising the security of industrial control systems and violating the standard's requirements for secure device management.
Vulnerability Details
CVE IDCVE-2017-16740
BSIDBS-2018-GLOBAL-227833-C BreachSpider Global ID
CVSS VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2018-01-09
Last Modified2024-11-21
ICS Relevance100%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

A Buffer Overflow issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1400 Controllers, Series B and C Versions 21.002 and earlier. The stack-based buffer overflow vulnerability has been identified, which may allow remote code execution.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability can be exploited remotely without authentication, requiring low skill level. An attacker can send a specially crafted packet to the controller, leading to a stack-based buffer overflow and potential remote code execution.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Rockwell Automation 1766-L32Awa
Rockwell Automation 1766-L32Awaa
Rockwell Automation 1766-L32Bwa
Rockwell Automation 1766-L32Bwaa
Rockwell Automation 1766-L32Bxb
Rockwell Automation 1766-L32Bxba
Rockwell Automation 1766-L32Bxba Firmware
Rockwell Automation 1766-L32Awa Firmware
Rockwell Automation 1766-L32Bxb Firmware
Rockwell Automation 1766-L32Bwaa Firmware
Rockwell Automation 1766-L32Awaa Firmware
Rockwell Automation 1766-L32Bwa Firmware
Remediation
View Vendor Advisory →

Remediation Priority: HIGH

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 3119 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement network segmentation and access controls to limit exposure to untrusted networks. Regularly monitor network traffic for suspicious activity.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R2
This CVE violates CIP-007-R2 as it allows unauthorized access to control systems, which could compromise the reliability of the bulk electric system.
IEC 62443: IEC 62443-3-3
This CVE maps to IEC 62443-3-3 because it involves a vulnerability that could lead to remote code execution, compromising the security of industrial control systems and violating the standard's requirements for secure device management.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash8f64135822d4831f7160d601a4139a9596e782607e41d10781cc256f10b712095a9c2222a749ac8da28dfd51ea601f70c65bc0c35d67ea0b73a98fc1197aa7df
Related CVEs affecting Rockwell Automation
CVE-2020-14516 10.0 In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.1... CVE-2012-4715 10.0 Buffer overflow in LogReceiver.exe in Rockwell Automation RSLinx Enterprise C... CVE-2009-3739 10.0 Multiple unspecified vulnerabilities on the Rockwell Automation AB Micrologix... CVE-2016-9343 10.0 An issue was discovered in Rockwell Automation Logix5000 Programmable Automat... CVE-2023-20198 10.0 Cisco is providing an update for the ongoing investigation into observed expl...
View all Rockwell Automation CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →