Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* before 28.011+ allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2016-2279
MEDIUMCVSS 6.1
6.1CVSS
EchelonGraph verdictMonitorLow exploitation likelihood right now — keep watching.
- Lower severity and no public exploit yet
CISA-KEV: Not listedEPSS PROB: —CVSS: 6.1Exploit: None knownExposed services: —
No fix is confirmed yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for the fix.
Internet exposure
The internet-exposure footprint is temporarily unavailable — the KEV-Exposure radar's record for this CVE could not be loaded just now. That is not a finding of zero exposed services; please retry shortly.
- CVSS v3
- 6.1
- EchelonGraph score
- Not yet assessedEchelonGraph has no severity assessment for this CVE yet. This is not a rating of zero.
- EG Score
- —
- EG Risk
- —
- EPSS PROB
- —
- EPSS %ILE
- —
- KEV
- Not listed
Published
March 2, 2016
Last Modified
June 17, 2026
References (6)
- ics-cert@hqhttp://www.securitytracker.com/id/1035190
- ics-cert@hqhttps://ics-cert.us-cert.gov/advisories/ICSA-16-061-02
- ics-cert@hqhttps://www.exploit-db.com/exploits/44626/
- af854a3a-2127-422b-91ae-364da2661108http://www.securitytracker.com/id/1035190
- af854a3a-2127-422b-91ae-364da2661108https://ics-cert.us-cert.gov/advisories/ICSA-16-061-02
- af854a3a-2127-422b-91ae-364da2661108https://www.exploit-db.com/exploits/44626/
Related CVEs(same CWE)
Frequently asked(4)
What is CVE-2016-2279?
CVE-2016-2279 is a medium vulnerability published on March 2, 2016. Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* before 28.011+ allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
When was CVE-2016-2279 disclosed?
CVE-2016-2279 was first published on March 2, 2016, with the most recent update on June 17, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
What is the CVSS score of CVE-2016-2279?
CVE-2016-2279 has a CVSS base score of 6.1.
How do I remediate CVE-2016-2279?
No fix for CVE-2016-2279 is confirmed yet. Until one is published, restrict network exposure of the affected system or apply the vendor's mitigation — for example, keep it off the internet or limit it to trusted networks — and watch the vendor's advisory for the fix.
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2016-2279
Is Your Infrastructure Affected by CVE-2016-2279?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.