Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-22659

Опубликовано: 25 мар. 2021
Источник: nvd
CVSS3: 8.6
CVSS2: 7.5
EPSS Низкий

Описание

Rockwell Automation MicroLogix 1400 Version 21.6 and below may allow a remote unauthenticated attacker to send a specially crafted Modbus packet allowing the attacker to retrieve or modify random values in the register. If successfully exploited, this may lead to a buffer overflow resulting in a denial-of-service condition. The FAULT LED will flash RED and communications may be lost. Recovery from denial-of-service condition requires the fault to be cleared by the user.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:rockwellautomation:micrologix_1400_firmware:*:*:*:*:*:*:*:*
Версия до 21.6 (включая)
cpe:2.3:h:rockwellautomation:micrologix_1400:-:*:*:*:*:*:*:*

EPSS

Процентиль: 72%
0.00707
Низкий

8.6 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-120

Связанные уязвимости

github
больше 3 лет назад

Rockwell Automation MicroLogix 1400 Version 21.6 and below may allow a remote unauthenticated attacker to send a specially crafted Modbus packet allowing the attacker to retrieve or modify random values in the register. If successfully exploited, this may lead to a buffer overflow resulting in a denial-of-service condition. The FAULT LED will flash RED and communications may be lost. Recovery from denial-of-service condition requires the fault to be cleared by the user.

EPSS

Процентиль: 72%
0.00707
Низкий

8.6 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-120