Vulnerability Intelligence Report
Rockwell Automation ControlLogix Communication Modules Vulnerable to Remote Code Execution
CVE-2023-3595
Where this vulnerability exists in the Rockwell Automation 1756 EN2* and 1756 EN3* ControlLogix communication products, it could allow a malicious user to perform remote code execution with persistence on the target system through maliciously crafted CIP messages. This includes the ability to modify, deny, and exfiltrate data passing through the device.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:3.64%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-787 ↗CWE-787 Out-of-bounds Write
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Rockwell Automation | 1756-EN2T Series A, B, C | <=5.008 & 5.028 (affected) |
| Rockwell Automation | 1756-EN2T Series D | <=11.003 (affected) |
| Rockwell Automation | 1756-EN2TK Series A, B, C | <=5.008 & 5.028 (affected) |
| Rockwell Automation | 1756-EN2TXT Series A, B, C | <=5.008 & 5.028 (affected) |
| Rockwell Automation | 1756-EN2TXT Series D | <=11.003 (affected) |
| Rockwell Automation | 1756-EN2TP Series A | <=11.003 (affected) |
| Rockwell Automation | 1756-EN2TPK Series A | <=11.003 (affected) |
| Rockwell Auotmation | 1756-EN2TPXT Series A | <=11.003 (affected) |
| Rockwell Automation | 1756-EN2TR Series A, B | <=5.008 & 5.028 (affected) |
| Rockwell Automation | 1756-EN2TR Series C | <=11.003 (affected) |
| Rockwell Automation | 1756-EN2TRK Series A, B | <=5.008 & 5.028 (affected) |
| Rockwell Automation | 1756-EN2TRK Series C | <=11.003 (affected) |
| Rockwell Automation | 1756-EN2TRXT Series A, B | <=5.008 & 5.028 (affected) |
| Rockwell Automation | 1756-EN2TRXT Series C | <=11.003 (affected) |
| Rockwell Automation | 1756-EN2F Series A, B | <=5.008 & 5.028 (affected) |
| Rockwell Automation | 1756-EN2F Series C | <=11.003 (affected) |
| Rockwell Automation | 1756-EN2FK Series A, B | <=5.008 & 5.028 (affected) |
| Rockwell Automation | 1756-EN2FK Series C | <=11.003 (affected) |
| Rockwell Automation | 1756-EN3TR Series A | <=5.008 & 5.028 (affected) |
| Rockwell Automation | 1756-EN3TR Series B | <=11.003 (affected) |
| Rockwell Automation | 1756-EN3TRK Series A | <=5.008 & 5.028 (affected) |
| Rockwell Automation | 1756-EN3TRK Series B | <=11.003 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
3.640%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Rockwell Automation · Vendor · USA |
| Reserved | 2023-07-10T15:34:52 |
| Published | 2023-07-12T12:37:01 |
| Patch Date | 2023-07-12 |
| Last Updated | 2024-08-02T07:01:57 |
Community Chatter & Buzz