In Rockwell Automation MicroLogix 1400 Controllers Series A, All Versions Series B, v15.002 and earlier, MicroLogix 1100 Controllers v14.00 and earlier, CompactLogix 5370 L1 controllers v30.014 and earlier, CompactLogix 5370 L2 controllers v30.014 and earlier, CompactLogix 5370 L3 controllers (includes CompactLogix GuardLogix controllers) v30.014 and earlier, an open redirect vulnerability could allow a remote unauthenticated attacker to input a malicious link to redirect users to a malicious site that could run or download arbitrary malware on the user’s machine.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Rockwellautomation
Subscribe
|
Compactlogix 5370 L1
Subscribe
Compactlogix 5370 L1 Firmware
Subscribe
Compactlogix 5370 L2
Subscribe
Compactlogix 5370 L2 Firmware
Subscribe
Compactlogix 5370 L3
Subscribe
Compactlogix 5370 L3 Firmware
Subscribe
Micrologix 1100
Subscribe
Micrologix 1100 Firmware
Subscribe
Micrologix 1400
Subscribe
Micrologix 1400 A Firmware
Subscribe
Micrologix 1400 B Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-2669 | In Rockwell Automation MicroLogix 1400 Controllers Series A, All Versions Series B, v15.002 and earlier, MicroLogix 1100 Controllers v14.00 and earlier, CompactLogix 5370 L1 controllers v30.014 and earlier, CompactLogix 5370 L2 controllers v30.014 and earlier, CompactLogix 5370 L3 controllers (includes CompactLogix GuardLogix controllers) v30.014 and earlier, an open redirect vulnerability could allow a remote unauthenticated attacker to input a malicious link to redirect users to a malicious site that could run or download arbitrary malware on the user’s machine. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-08-04T22:40:15.190Z
Reserved: 2019-04-08T00:00:00
Link: CVE-2019-10955
No data.
Status : Modified
Published: 2019-04-25T18:29:00.397
Modified: 2024-11-21T04:20:13.710
Link: CVE-2019-10955
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD