← back
CVE-2023-3595criticalobserved exploitationCWE-787

Rockwell Automation ControlLogix Communication Modules Vulnerable to Remote Code Execution

50Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Actcvss 9.8epss 5.5%
from disclosure to weapon
Published on NVDJul 12
VulnCheck+223d
exploitation probability
5.5%top 8% of all CVEs
observed exploitation
yesVulnCheck
Where this vulnerability exists in the Rockwell Automation 1756 EN2* and 1756 EN3* ControlLogix communication products, it could allow a malicious user to perform remote code execution with persistence on the target system through maliciously crafted CIP messages. This includes the ability to modify, deny, and exfiltrate data passing through the device.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H