CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2017-16740: Modbus TCP Buffer Overflow in Rockwell MicroLogix 1400

August 6, 2026

CVE-2017-16740 is a buffer overflow vulnerability in the Modbus TCP implementation of Rockwell Automation MicroLogix 1400 Series B and C controllers running firmware 21.002 and earlier. With a CVSS score of 8.6, exploitation could allow remote attackers to cause a denial of service or potentially execute arbitrary code. Rockwell addressed the flaw in firmware revision 21.003. The vulnerability was highlighted in the context of exposed PLCs in water utility attacks, though exploitation requires Modbus TCP to be enabled.