PT-2023-3019 · Rockwell Automation · Kinetix 5500 Drives

CVE-2023-1834

·

Publicado

2023-05-11

·

Atualizado

2023-05-22

CVSS v2.0

9.7

Crítica

VetorAV:N/AC:L/Au:N/C:P/I:C/A:C
Name of the Vulnerable Software and Affected Versions Kinetix 5500 drives version 7.13
Description The issue is related to inadequate access control in the Kinetix 5500 drives' firmware, which may allow unauthorized access to the device through open telnet and FTP ports. This could potentially enable attackers to gain access to the device. The affected devices were manufactured between May 2022 and January 2023.
Recommendations For Kinetix 5500 drives version 7.13, consider disabling the telnet and FTP ports as a temporary workaround to minimize the risk of exploitation. Restrict access to these ports to prevent unauthorized access to the device.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-03083
CVE-2023-1834

Produtos afetados

Kinetix 5500 Drives