Vulnerability Description
Where this vulnerability exists in the Rockwell Automation 1756 EN2* and 1756 EN3* ControlLogix communication products, it could allow a malicious user to perform remote code execution with persistence on the target system through maliciously crafted CIP messages. This includes the ability to modify, deny, and exfiltrate data passing through the device.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rockwellautomation | 1756-En2F Series A Firmware | - |
| Rockwellautomation | 1756-En2F Series A | - |
| Rockwellautomation | 1756-En2F Series B Firmware | - |
| Rockwellautomation | 1756-En2F Series B | - |
| Rockwellautomation | 1756-En2F Series C Firmware | - |
| Rockwellautomation | 1756-En2F Series C | - |
| Rockwellautomation | 1756-En2T Series A Firmware | - |
| Rockwellautomation | 1756-En2T Series A | - |
| Rockwellautomation | 1756-En2T Series B Firmware | - |
| Rockwellautomation | 1756-En2T Series B | - |
| Rockwellautomation | 1756-En2T Series C Firmware | - |
| Rockwellautomation | 1756-En2T Series C | - |
| Rockwellautomation | 1756-En2T Series D Firmware | - |
| Rockwellautomation | 1756-En2T Series D | - |
| Rockwellautomation | 1756-En2Tr Series A Firmware | - |
| Rockwellautomation | 1756-En2Tr Series A | - |
| Rockwellautomation | 1756-En2Tr Series B Firmware | - |
| Rockwellautomation | 1756-En2Tr Series B | - |
| Rockwellautomation | 1756-En2Tr Series C Firmware | - |
| Rockwellautomation | 1756-En2Tr Series C | - |
Related Weaknesses (CWE)
References
- https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1140010Permissions RequiredVendor Advisory
- https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1140010Permissions RequiredVendor Advisory
FAQ
What is CVE-2023-3595?
CVE-2023-3595 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Where this vulnerability exists in the Rockwell Automation 1756 EN2* and 1756 EN3* ControlLogix communication products, it could allow a malicious user to perform remote code execution with persisten...
How severe is CVE-2023-3595?
CVE-2023-3595 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-3595?
Check the references section above for vendor advisories and patch information. Affected products include: Rockwellautomation 1756-En2F Series A Firmware, Rockwellautomation 1756-En2F Series A, Rockwellautomation 1756-En2F Series B Firmware, Rockwellautomation 1756-En2F Series B, Rockwellautomation 1756-En2F Series C Firmware.