PT-2019-4257 · Rockwell Automation · Compactlogix 5370 L2+4

Published

2019-04-25

·

Updated

2020-02-10

·

CVE-2019-10955

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions MicroLogix 1400 versions A through B MicroLogix 1100 versions prior to v14.00 CompactLogix 5370 L1 versions prior to v30.014 CompactLogix 5370 L2 versions prior to v30.014 CompactLogix 5370 L3 versions prior to v30.014
Description The issue is related to an open redirect vulnerability that could allow a remote unauthenticated attacker to input a malicious link and redirect users to a malicious site, potentially running or downloading arbitrary malware on the user's machine. This is achieved by exploiting the vulnerability to redirect the user to a non-trusted site using a specially crafted URL.
Recommendations For MicroLogix 1400 versions A through B, update to a version later than Series B. For MicroLogix 1100 versions prior to v14.00, update to a version later than v14.00. For CompactLogix 5370 L1 versions prior to v30.014, update to a version later than v30.014. For CompactLogix 5370 L2 versions prior to v30.014, update to a version later than v30.014. For CompactLogix 5370 L3 versions prior to v30.014, update to a version later than v30.014.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-04858
CVE-2019-10955

Affected Products

Compactlogix 5370 L1
Compactlogix 5370 L2
Compactlogix 5370 L3
Micrologix 1100
Micrologix 1400