Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* before 28.011+ allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Advisories
Source ID Title
EUVD EUVD EUVD-2016-3363 Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* before 28.011+ allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 03 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-06-03T13:44:03.190Z

Reserved: 2016-02-09T00:00:00.000Z

Link: CVE-2016-2279

cve-icon Vulnrichment

Updated: 2024-08-05T23:24:48.329Z

cve-icon NVD

Status : Modified

Published: 2016-03-02T11:59:03.723

Modified: 2026-06-17T00:43:44.763

Link: CVE-2016-2279

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses