Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fvq9-7g3p-r5g2

Опубликовано: 14 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.2

Описание

A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate revocation handling. The security issue stems from the controller failing to properly reject certificates signed by an intermediate certificate that has been revoked via a Certificate Revocation List (CRL). This could allow a network-based attacker to establish a connection using a certificate that should be untrusted, potentially bypassing CIP Security protections.

A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate revocation handling. The security issue stems from the controller failing to properly reject certificates signed by an intermediate certificate that has been revoked via a Certificate Revocation List (CRL). This could allow a network-based attacker to establish a connection using a certificate that should be untrusted, potentially bypassing CIP Security protections.

EPSS

Процентиль: 4%
0.0014
Низкий

8.2 High

CVSS4

Дефекты

CWE-299

Связанные уязвимости

nvd
17 дней назад

A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate revocation handling. The security issue stems from the controller failing to properly reject certificates signed by an intermediate certificate that has been revoked via a Certificate Revocation List (CRL). This could allow a network-based attacker to establish a connection using a certificate that should be untrusted, potentially bypassing CIP Security protections.

CVSS3: 5.9
fstec
18 дней назад

Уязвимость функции Certificate Revocation List (CRL) микропрограммного обеспечения программируемых логических контроллеров Rockwell Automation ControlLogix 5580, GuardLogix 5580, CompactLogix 5380 и Compact GuardLogix 5380, позволяющая нарушителю обойти ограничения безопасности

EPSS

Процентиль: 4%
0.0014
Низкий

8.2 High

CVSS4

Дефекты

CWE-299