CVE-2017-16740
A Buffer Overflow issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1400 Controllers, Series B and C Versions 21.002 and earlier. The stack-based buffer overflow vulnerability ha...
Affects 12 products across 1 vendor.
Parent class for buffer-related vulnerabilities where operations exceed buffer boundaries.
Program copies data to a buffer without verifying the source data fits within the destination.
Show all 14
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A critical buffer overflow vulnerability exists in Rockwell Automation Allen-Bradley MicroLogix 1400 Controllers, Series B and C, versions 21.002 and earlier. This vulnerability could allow remote code execution, posing significant risks to operational safety and system integrity.
BSID: BS-2018-GLOBAL-227833-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2017-16740?
What is the CVSS score for CVE-2017-16740?
Is CVE-2017-16740 actively exploited?
How do I remediate CVE-2017-16740?
What systems are affected by CVE-2017-16740?
What NERC-CIP standard applies to CVE-2017-16740?
What IEC 62443 requirement maps to CVE-2017-16740?
| CVE ID | CVE-2017-16740 |
|---|---|
| BSID | BS-2018-GLOBAL-227833-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Published | 2018-01-09 |
| Last Modified | 2024-11-21 |
| ICS Relevance | 100% |
| Weakness (CWE) | |
| Verticals | |
| Source | NVD |
A Buffer Overflow issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1400 Controllers, Series B and C Versions 21.002 and earlier. The stack-based buffer overflow vulnerability has been identified, which may allow remote code execution.
Source: NIST NVD / MITRE CVE Database
The vulnerability can be exploited remotely without authentication, requiring low skill level. An attacker can send a specially crafted packet to the controller, leading to a stack-based buffer overflow and potential remote code execution.
Exploitation Likelihood: MEDIUM
| Vendor | Product | Fixed Version |
|---|---|---|
| Rockwell Automation | 1766-L32Awa | — |
| Rockwell Automation | 1766-L32Awaa | — |
| Rockwell Automation | 1766-L32Bwa | — |
| Rockwell Automation | 1766-L32Bwaa | — |
| Rockwell Automation | 1766-L32Bxb | — |
| Rockwell Automation | 1766-L32Bxba | — |
| Rockwell Automation | 1766-L32Bxba Firmware | — |
| Rockwell Automation | 1766-L32Awa Firmware | — |
| Rockwell Automation | 1766-L32Bxb Firmware | — |
| Rockwell Automation | 1766-L32Bwaa Firmware | — |
| Rockwell Automation | 1766-L32Awaa Firmware | — |
| Rockwell Automation | 1766-L32Bwa Firmware | — |
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Implement network segmentation and access controls to limit exposure to untrusted networks. Regularly monitor network traffic for suspicious activity.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.
This CVE violates CIP-007-R2 as it allows unauthorized access to control systems, which could compromise the reliability of the bulk electric system.
This CVE maps to IEC 62443-3-3 because it involves a vulnerability that could lead to remote code execution, compromising the security of industrial control systems and violating the standard's requirements for secure device management.
Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.
SAGE Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 8f64135822d4831f7160d601a4139a9596e782607e41d10781cc256f10b712095a9c2222a749ac8da28dfd51ea601f70c65bc0c35d67ea0b73a98fc1197aa7df |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →