CVE-2017-7914

A Missing Authorization issue was discovered in Rockwell Automation PanelView Plus 6 700-1500 6.00.04, 6.00.05, 6.00.42, 6.00-20140306, 6.10.20121012, 6.10-20140122, 7.00-20121012, 7.00-20130108, 7.00-20130325, 7.00-20130619, 7.00-20140128, 7.00-20140310, 7.00-20140429, 7.00-20140621, 7.00-20140729, 7.00-20141022, 8.00-20140730, and 8.00-20141023. There is no authorization check when connecting to the device, allowing an attacker remote access.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
icscertCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
VendorProductVersion
rockwellautomationpanelview_plus_6_700-1500_firmware
6.00-20140306
rockwellautomationpanelview_plus_6_700-1500_firmware
6.00.04
rockwellautomationpanelview_plus_6_700-1500_firmware
6.00.05
rockwellautomationpanelview_plus_6_700-1500_firmware
6.00.42
rockwellautomationpanelview_plus_6_700-1500_firmware
6.10-20140122
rockwellautomationpanelview_plus_6_700-1500_firmware
6.10.20121012
rockwellautomationpanelview_plus_6_700-1500_firmware
7.00-20121012
rockwellautomationpanelview_plus_6_700-1500_firmware
7.00-20130108
rockwellautomationpanelview_plus_6_700-1500_firmware
7.00-20130325
rockwellautomationpanelview_plus_6_700-1500_firmware
7.00-20130619
rockwellautomationpanelview_plus_6_700-1500_firmware
7.00-20140128
rockwellautomationpanelview_plus_6_700-1500_firmware
7.00-20140310
rockwellautomationpanelview_plus_6_700-1500_firmware
7.00-20140429
rockwellautomationpanelview_plus_6_700-1500_firmware
7.00-20140621
rockwellautomationpanelview_plus_6_700-1500_firmware
7.00-20140729
rockwellautomationpanelview_plus_6_700-1500_firmware
7.00-20141022
rockwellautomationpanelview_plus_6_700-1500_firmware
8.00-20140730
rockwellautomationpanelview_plus_6_700-1500_firmware
8.00-20141023
𝑥
= Vulnerable software versions