Vulnerability Description
Rockwell Automation was made aware that Kinetix 5500 drives, manufactured between May 2022 and January 2023, and are running v7.13 may have the telnet and FTP ports open by default. This could potentially allow attackers unauthorized access to the device through the open ports.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rockwellautomation | Kinetix 5500 Firmware | 7.13 |
| Rockwellautomation | Kinetix 5500 | - |
Related Weaknesses (CWE)
References
- https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1139441Permissions Required
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-131-09Third Party AdvisoryUS Government Resource
- https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1139441Permissions Required
FAQ
What is CVE-2023-1834?
CVE-2023-1834 is a vulnerability with a CVSS score of 9.4 (CRITICAL). Rockwell Automation was made aware that Kinetix 5500 drives, manufactured between May 2022 and January 2023, and are running v7.13 may have the telnet and FTP ports open by default. This could poten...
How severe is CVE-2023-1834?
CVE-2023-1834 has been rated CRITICAL with a CVSS base score of 9.4/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-1834?
Check the references section above for vendor advisories and patch information. Affected products include: Rockwellautomation Kinetix 5500 Firmware, Rockwellautomation Kinetix 5500.