← voltar
CVE-2023-3595criticalexploração observadaCWE-787

Rockwell Automation ControlLogix Communication Modules Vulnerable to Remote Code Execution

50Vexday Risk Score

Priorize a correção. Ela exploração observada pelo VulnCheck.

ssvc Actcvss 9.8epss 5.5%
da publicação à arma
Publicada no NVD12 de jul.
VulnCheck+223d
probabilidade de exploração
5.5%top 8% das CVEs
exploração observada
simVulnCheck
Where this vulnerability exists in the Rockwell Automation 1756 EN2* and 1756 EN3* ControlLogix communication products, it could allow a malicious user to perform remote code execution with persistence on the target system through maliciously crafted CIP messages. This includes the ability to modify, deny, and exfiltrate data passing through the device.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H