MEDIUM🇬🇧 English

CVE-2019-10955

CVSS 6.1v3.0pub. 2019-04-25upd. 2026-06-03

In Rockwell Automation MicroLogix 1400 Controllers Series A, All Versions Series B, v15.002 and earlier, MicroLogix 1100 Controllers v14.00 and earlier, CompactLogix 5370 L1 controllers v30.014 and earlier, CompactLogix 5370 L2 controllers v30.014 and earlier, CompactLogix 5370 L3 controllers (includes CompactLogix GuardLogix controllers) v30.014 and earlier, an open redirect vulnerability could allow a remote unauthenticated attacker to input a malicious link to redirect users to a malicious site that could run or download arbitrary malware on the user’s machine.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • Rockwellautomation Compactlogix 5370 L1

    HW
    Rockwellautomation
    wszystkie wersje
  • Rockwellautomation Compactlogix 5370 L1 Firmware

    OS
    Rockwellautomation
    ≤ 30.014
  • Rockwellautomation Compactlogix 5370 L2

    HW
    Rockwellautomation
    wszystkie wersje
  • Rockwellautomation Compactlogix 5370 L2 Firmware

    OS
    Rockwellautomation
    ≤ 30.014
  • Rockwellautomation Compactlogix 5370 L3

    HW
    Rockwellautomation
    wszystkie wersje
  • Rockwellautomation Compactlogix 5370 L3 Firmware

    OS
    Rockwellautomation
    ≤ 30.014
  • Rockwellautomation Micrologix 1100

    HW
    Rockwellautomation
    wszystkie wersje
  • Rockwellautomation Micrologix 1100 Firmware

    OS
    Rockwellautomation
    ≤ 14.00
  • Rockwellautomation Micrologix 1400

    HW
    Rockwellautomation
    wszystkie wersje
  • Rockwellautomation Micrologix 1400 A Firmware

    OS
    Rockwellautomation
    wszystkie wersje
  • Rockwellautomation Micrologix 1400 B Firmware

    OS
    Rockwellautomation
    ≤ 15.002
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Auth Bypass
CWE
Referencje

Powiązane podatności

CVE-2022-1161CRITICAL10.0PL ✓ten sam produkt

Rozbieżność kodu wykonywalnego i czytelnego w sterownikach Rockwell Automation Logix

CVE-2020-6990CRITICAL9.8PL ✓ten sam produkt

Hardkodowany klucz kryptograficzny w sterownikach Rockwell Automation MicroLogix

CVE-2019-10952CRITICAL9.8PL ✓ten sam produkt

RCE i DoS w kontrolerach Rockwell Automation CompactLogix 5370 via HTTP/HTTPS

CVE-2017-14465CRITICAL9.8PL ✓ten sam produkt

Nieautoryzowany dostęp do plików danych i logiki PLC w Allen Bradley MicroLogix 1400

CVE-2017-14463CRITICAL9.8PL ✓ten sam produkt

Brak kontroli dostępu w Allen Bradley MicroLogix 1400 — nieautoryzowany odczyt/zapis