HIGH🇵🇱 Wersja polska

CVE-2019-10954

CVSS 7.5v3.1pub. 2019-05-01upd. 2026-02-20

An attacker could send crafted SMTP packets to cause a denial-of-service condition where the controller enters a major non-recoverable faulted state (MNRF) in CompactLogix 5370 L1, L2, and L3 Controllers, Compact GuardLogix 5370 controllers, and Armor Compact GuardLogix 5370 Controllers Versions 20 - 30 and earlier.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Rockwellautomation Armor Compact Guardlogix 5370

    HW
    Rockwellautomation
    all versions
  • Rockwellautomation Armor Compact Guardlogix 5370 Firmware

    OS
    Rockwellautomation
    20.011 – 30.014
  • Rockwellautomation Compact Guardlogix 5370

    HW
    Rockwellautomation
    all versions
  • Rockwellautomation Compact Guardlogix 5370 Firmware

    OS
    Rockwellautomation
    20.011 – 30.014
  • Rockwellautomation Compactlogix 5370 L1

    HW
    Rockwellautomation
    all versions
  • Rockwellautomation Compactlogix 5370 L1 Firmware

    OS
    Rockwellautomation
    20.011 – 30.014
  • Rockwellautomation Compactlogix 5370 L2

    HW
    Rockwellautomation
    all versions
  • Rockwellautomation Compactlogix 5370 L2 Firmware

    OS
    Rockwellautomation
    20.011 – 30.014
  • Rockwellautomation Compactlogix 5370 L3

    HW
    Rockwellautomation
    all versions
  • Rockwellautomation Compactlogix 5370 L3 Firmware

    OS
    Rockwellautomation
    20.011 – 30.014
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2021-22681CRITICAL9.8⚠ KEVPL ✓same product

Rockwell Automation — pominięcie weryfikacji klucza uwierzytelnienia w sterownikach Logix

CVE-2022-1161CRITICAL10.0PL ✓same product

Rozbieżność kodu wykonywalnego i czytelnego w sterownikach Rockwell Automation Logix

CVE-2019-10952CRITICAL9.8PL ✓same product

RCE i DoS w kontrolerach Rockwell Automation CompactLogix 5370 via HTTP/HTTPS

CVE-2022-3157HIGH8.6same product

A vulnerability exists in the Rockwell Automation controllers that allows a malformed CIP request to cause a ...

CVE-2020-6998MEDIUM5.8same product

The connection establishment algorithm found in Rockwell Automation CompactLogix 5370 and ControlLogix 5570 ve...