Vulnerability Intelligence Report
CVE-2016-5645
Rockwell Automation MicroLogix 1400 PLC 1766-L32BWA, 1766-L32AWA, 1766-L32BXB, 1766-L32BWAA, 1766-L32AWAA, and 1766-L32BXBA devices have a hardcoded SNMP community, which makes it easier for remote attackers to load arbitrary firmware updates by leveraging knowledge of this community.
No Active Exploit Signals
CVSS Base Score
7.3
HIGH
Exploitability:3.9
Impact Score:3.4
EPSS Probability:29.40%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-798 ↗CWE-798 Use of Hard-coded Credentials
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| rockwellautomation | 1766-l32awa | all |
| rockwellautomation | 1766-l32awaa | all |
| rockwellautomation | 1766-l32bwa | all |
| rockwellautomation | 1766-l32bwaa | all |
| rockwellautomation | 1766-l32bxb | all |
| rockwellautomation | 1766-l32bxba | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
29.398%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | CERT/CC · CERT · USA |
| Reserved | 2016-06-16T00:00:00 |
| Published | 2016-08-24T01:00:00 |
| Patch Date | 2016-08-11 |
| Last Updated | 2026-06-03T13:14:58 |
Community Chatter & Buzz