CRITICAL · 9.4

CVE-2023-1834

Rockwell Automation was made aware that Kinetix 5500 drives, manufactured between May 2022 and January 2023, and are running v7.13 may have the telnet and FTP ports open by default.  This could poten...

Vulnerability Description

Rockwell Automation was made aware that Kinetix 5500 drives, manufactured between May 2022 and January 2023, and are running v7.13 may have the telnet and FTP ports open by default.  This could potentially allow attackers unauthorized access to the device through the open ports.

CVSS Score

9.4

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
RockwellautomationKinetix 5500 Firmware7.13
RockwellautomationKinetix 5500-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-1834?

CVE-2023-1834 is a vulnerability with a CVSS score of 9.4 (CRITICAL). Rockwell Automation was made aware that Kinetix 5500 drives, manufactured between May 2022 and January 2023, and are running v7.13 may have the telnet and FTP ports open by default.  This could poten...

How severe is CVE-2023-1834?

CVE-2023-1834 has been rated CRITICAL with a CVSS base score of 9.4/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2023-1834?

Check the references section above for vendor advisories and patch information. Affected products include: Rockwellautomation Kinetix 5500 Firmware, Rockwellautomation Kinetix 5500.