Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gpr8-p742-hw62

Опубликовано: 16 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.3

Описание

A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Connection IDs on the diagnostics webpage, which are accessible to any unauthenticated user on the network. This information can be leveraged by an attacker to construct malicious packets, leading to Denial-of-Service.

A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Connection IDs on the diagnostics webpage, which are accessible to any unauthenticated user on the network. This information can be leveraged by an attacker to construct malicious packets, leading to Denial-of-Service.

EPSS

Процентиль: 22%
0.00298
Низкий

6.3 Medium

CVSS4

Дефекты

CWE-497

Связанные уязвимости

nvd
около 2 месяцев назад

A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Connection IDs on the diagnostics webpage, which are accessible to any unauthenticated user on the network. This information can be leveraged by an attacker to construct malicious packets, leading to Denial-of-Service.

EPSS

Процентиль: 22%
0.00298
Низкий

6.3 Medium

CVSS4

Дефекты

CWE-497