PT-2019-12099 · Rockwell Automation · Armor Compact Guardlogix 5370+2

George Lashenko

+1

·

Publicado

2019-05-01

·

Atualizado

2026-02-20

·

CVE-2019-10952

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CompactLogix 5370 L1, L2, and L3 Controllers, Compact GuardLogix 5370 controllers, and Armor Compact GuardLogix 5370 Controllers versions 20 through 30 and earlier.
Description An attacker could send a crafted HTTP/HTTPS request to render the web server unavailable and/or lead to remote code execution caused by a stack-based buffer overflow vulnerability. A cold restart is required for recovering.
Recommendations For versions 20 through 30 and earlier, a cold restart is required to recover from the issue. As a temporary workaround, consider restricting access to the web server to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Resource Exhaustion

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-10952

Produtos afetados

Armor Compact Guardlogix 5370
Compact Guardlogix 5370
Compactlogix 5370