ZeroHour

CVE-2023-2262

CVSS 3.1
9.8 critical
EPSS
<1%p60
Published
()
Modified
Description

A buffer overflow vulnerability exists in the Rockwell Automation select 1756-EN* communication devices. If exploited, a threat actor could potentially leverage this vulnerability to perform a remote code execution. To exploit this vulnerability, a threat actor would have to send a maliciously crafted CIP request to device.

Vendors
rockwellautomation
Products
1756-en2t series a firmware, 1756-en2t series b firmware, 1756-en2t series c firmware, 1756-en2t series d firmware, 1756-en2tk series a firmware, 1756-en2tk series b firmware, 1756-en2tk series c firmware, 1756-en2txt series a firmware, 1756-en2txt series b firmware, 1756-en2txt series c firmware, 1756-en2txt series d firmware, 1756-en2tp series a firmware
Weakness
CWE-121, CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.