MEDIUM · 6.1

CVE-2019-10955

In Rockwell Automation MicroLogix 1400 Controllers Series A, All Versions Series B, v15.002 and earlier, MicroLogix 1100 Controllers v14.00 and earlier, CompactLogix 5370 L1 controllers v30.014 and ea...

Vulnerability Description

In Rockwell Automation MicroLogix 1400 Controllers Series A, All Versions Series B, v15.002 and earlier, MicroLogix 1100 Controllers v14.00 and earlier, CompactLogix 5370 L1 controllers v30.014 and earlier, CompactLogix 5370 L2 controllers v30.014 and earlier, CompactLogix 5370 L3 controllers (includes CompactLogix GuardLogix controllers) v30.014 and earlier, an open redirect vulnerability could allow a remote unauthenticated attacker to input a malicious link to redirect users to a malicious site that could run or download arbitrary malware on the user’s machine.

CVSS Score

6.1

MEDIUM

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
RockwellautomationMicrologix 1400 A FirmwareAll versions
RockwellautomationMicrologix 1400 B Firmware<= 15.002
RockwellautomationMicrologix 1400-
RockwellautomationMicrologix 1100 Firmware<= 14.00
RockwellautomationMicrologix 1100-
RockwellautomationCompactlogix 5370 L1 Firmware<= 30.014
RockwellautomationCompactlogix 5370 L1-
RockwellautomationCompactlogix 5370 L2 Firmware<= 30.014
RockwellautomationCompactlogix 5370 L2-
RockwellautomationCompactlogix 5370 L3 Firmware<= 30.014
RockwellautomationCompactlogix 5370 L3-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-10955?

CVE-2019-10955 is a vulnerability with a CVSS score of 6.1 (MEDIUM). In Rockwell Automation MicroLogix 1400 Controllers Series A, All Versions Series B, v15.002 and earlier, MicroLogix 1100 Controllers v14.00 and earlier, CompactLogix 5370 L1 controllers v30.014 and ea...

How severe is CVE-2019-10955?

CVE-2019-10955 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-10955?

Check the references section above for vendor advisories and patch information. Affected products include: Rockwellautomation Micrologix 1400 A Firmware, Rockwellautomation Micrologix 1400 B Firmware, Rockwellautomation Micrologix 1400, Rockwellautomation Micrologix 1100 Firmware, Rockwellautomation Micrologix 1100.