SB2017060811 - Access bypass in Rockwell Automation PanelView Plus 6 700-1500
Published: June 8, 2017
Security Bulletin ID
SB2017060811
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Access bypass (CVE-ID: CVE-2017-7914)
The vulnerability allows a remote attacker to gain access to the target system.The weakness exists due to insufficient implementation of access control mechanisms. A remote attacker can access the device and obtain potentially sensitive data or cause the device to crash.
Successful exploitation of the vulnerability may result in information disclosure or denial of service.
Remediation
Install update from vendor's website.