Rockwell Automation Allen-Bradley ControlLogix Communication Modules vulnerable to Denial of Service
CVE-2023-3596

7.5HIGH

Key Information:

Badges

📰 News Worthy

Summary

The vulnerability present in Rockwell Automation's 1756-EN4 Ethernet/IP communication products allows attackers to potentially disrupt service by sending maliciously crafted CIP messages. This could lead to a denial of service, affecting the availability and performance of the network communication systems. Organizations utilizing these products should assess their cybersecurity measures and apply necessary updates to mitigate risks.

Affected Version(s)

1756-EN4TR Series A <=5.001

1756-EN4TRK Series A <=5.001

1756-EN4TRXT Series A <=5.001

News Articles

Rockwell Automation ControlLogix Bugs Expose Industrial Systems to Remote Attacks

U.S. CISA warns of critical vulnerabilities in Rockwell Automation ControlLogix ENIP modules, allowing remote code execution and DoS attacks.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 📰

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

.