← Vulnerability feed

Vulnerability record · CVE-2017-7902 · published 30 June 2017

CVE-2017-7902: Rockwellautomation 1763-l16awa series a vulnerability

Rockwellautomation · 1763 L16awa Series A

A "Reusing a Nonce, Key Pair in Encryption" issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prior versions; 1763-L16BBB, Series A and B, Version 16.00 and prior versions; 1763-L16BWA, Series A and B, Version 16.00 and prior versions; and 1763-L16DWD, Series A and B, Version 16.00 and prior versions and Allen-Bradley MicroLogix 1400 programmable logic controllers 1766-L32AWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWAA, Series A and B, Version 16.00 and prior versions; 1766-L32BXB, Series A and B, Version 16.00 and prior versions; 1766-L32BXBA, Series A and B, Version 16.00 and prior versions; and 1766-L32AWAA, Series A and B, Version 16.00 and prior versions. The affected product reuses nonces, which may allow an attacker to capture and replay a valid request until the nonce is changed.

9.8 CVSS 3.0 Critical EPSS 2.6% · top 15.5% CWE-323 · CWE-323CWE-330 · CWE-330
9.8CVSS 3.0 base score, v2 5.0
2.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
20Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A "Reusing a Nonce, Key Pair in Encryption" issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prior versions; 1763-L16BBB, Series A and B, Version 16.00 and prior versions; 1763-L16BWA, Series A and B, Version 16.00 and prior versions; and 1763-L16DWD, Series A and B, Version 16.00 and prior versions and Allen-Bradley MicroLogix 1400 programmable logic controllers 1766-L32AWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWAA, Series A and B, Version 16.00 and prior versions; 1766-L32BXB, Series A and B, Version 16.00 and prior versions; 1766-L32BXBA, Series A and B, Version 16.00 and prior versions; and 1766-L32AWAA, Series A and B, Version 16.00 and prior versions. The affected product reuses nonces, which may allow an attacker to capture and replay a valid request until the nonce is changed.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

20 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securitytracker.com/id/1038546 Third Party AdvisoryVDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-17-115-04 PatchThird Party AdvisoryUS Government Resource
http://www.securitytracker.com/id/1038546 Third Party AdvisoryVDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-17-115-04 PatchThird Party AdvisoryUS Government Resource

Track CVE-2017-7902 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-7898Rockwellautomation 1763-l16awa series a improper restriction of authentication attempts vulnerabilityAn Improper Restriction of Excessive Authentication Attempts issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-l…EPSS 5.2%9.8CVE-2017-7899Rockwellautomation 1763-l16awa series a information exposure vulnerabilityAn Information Exposure issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series …EPSS 4.7%9.8CVE-2017-7903Rockwellautomation 1763-l16awa series a weak password requirements vulnerabilityA Weak Password Requirements issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Se…EPSS 2.8%9.8CVE-2016-0868Rockwellautomation 1763-l16awa series a memory buffer overflow vulnerabilityStack-based buffer overflow on Rockwell Automation Allen-Bradley MicroLogix 1100 devices A through 15.000 and B before 15.002 allows remote attackers…EPSS 8.9%8.6CVE-2017-7901Rockwellautomation 1763-l16awa series a vulnerabilityA Predictable Value Range from Previous Values issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controlle…EPSS 6.7%7.3CVE-2016-9334Rockwellautomation 1763-l16awa series a vulnerabilityAn issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 controller 1763-L16AWA, Series A and B, Version 14.000 and prior version…EPSS 4.1%2.7CVE-2016-9338Rockwellautomation 1763-l16awa series a vulnerabilityAn issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 controller 1763-L16AWA, Series A and B, Version 14.000 and prior version…EPSS 2.4%

Source: NIST National Vulnerability Database (record CVE-2017-7902), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.