SB2017060811 - Access bypass in Rockwell Automation PanelView Plus 6 700-1500



SB2017060811 - Access bypass in Rockwell Automation PanelView Plus 6 700-1500

Published: June 8, 2017

Security Bulletin ID SB2017060811
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Access bypass (CVE-ID: CVE-2017-7914)

The vulnerability allows a remote attacker to gain access to the target system.

The weakness exists due to insufficient implementation of access control mechanisms. A remote attacker can access the device and obtain potentially sensitive data or cause the device to crash.

Successful exploitation of the vulnerability may result in information disclosure or denial of service.

Remediation

Install update from vendor's website.