CVE-2017-16740Active Exploitation(rockwellautomation / 1766-l32awa)

MEDIUMCVSS 10.0 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for rockwellautomation 1766-l32awa systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A Buffer Overflow issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1400 Controllers, Series B and C Versions 21.002 and earlier. The stack-based buffer overflow vulnerability has been identified, which may allow remote code execution.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-120CWE-119

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 1766-l32awa
  • 1766-l32awa_firmware
  • 1766-l32awaa
  • 1766-l32awaa_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
1766-l32awa1766-l32awa_firmware1766-l32awaa1766-l32awaa_firmware1766-l32bwa1766-l32bwa_firmware1766-l32bwaa1766-l32bwaa_firmware1766-l32bxb1766-l32bxb_firmware

1 version affected across 12 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-07: 1Active Exploitation · 2026-08-07: 1Technical Details · 2026-08-07: 108-07
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers exploited internet-exposed Rockwell controllers across 12 U.S. states, escalating privileges via CVE-2017-16740 to disrupt water systems. Lateral movement through interconnected control networks enabled widespread operational impact including pressure loss and flooding. Runtime segmentation could have limited blast radius across critical infrastructure. #CriticalInfrastructure #ICS 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/exposed-rockwell-controllers-water-system-attacks-2026

    Post summary

    Attackers actively exploited CVE‑2017‑16740 on exposed Rockwell controllers, causing widespread operational disruptions to water systems across 12 U.S. states.

    0000062
    1.9K followersView on X
CPE platform detail12 entries

12 of 12 entries

PartVendorProductVersionTarget SWTarget HW
HWrockwellautomation1766-l32awa---
OSrockwellautomation1766-l32awa_firmware---
HWrockwellautomation1766-l32awaa---
OSrockwellautomation1766-l32awaa_firmware---
HWrockwellautomation1766-l32bwa---
OSrockwellautomation1766-l32bwa_firmware---
HWrockwellautomation1766-l32bwaa---
OSrockwellautomation1766-l32bwaa_firmware---
HWrockwellautomation1766-l32bxb---
OSrockwellautomation1766-l32bxb_firmware---
HWrockwellautomation1766-l32bxba---
OSrockwellautomation1766-l32bxba_firmware---

Explore more