Required CVE Record Information
Description
An attacker could send a crafted HTTP/HTTPS request to render the web server unavailable and/or lead to remote code execution caused by a stack-based buffer overflow vulnerability. A cold restart is required for recovering CompactLogix 5370 L1, L2, and L3 Controllers, Compact GuardLogix 5370 controllers, and Armor Compact GuardLogix 5370 Controllers Versions 20 - 30 and earlier.
Product Status
Learn moreVersions 1 Total
Default Status: unaffected
affected
Versions 1 Total
Default Status: unaffected
affected
Versions 1 Total
Default Status: unaffected
affected
Versions 1 Total
Default Status: unaffected
affected
Versions 1 Total
Default Status: unaffected
affected
Credits
- Younes Dragoni of Nozomi Networks of CyberX reported to CISA. finder
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 3 Total
- https://ics-cert.us-cert.gov/advisories/ICSA-19-120-01 x_transferred
- securityfocus.com: 108118 vdb-entryx_transferred
- https://rockwellautomation.custhelp.com/app/answers/detail/a_id/1075979 x_transferred