Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-9636

Опубликовано: 14 июл. 2026
Источник: nvd
EPSS Низкий

Описание

A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate revocation handling. The security issue stems from the controller failing to properly reject certificates signed by an intermediate certificate that has been revoked via a Certificate Revocation List (CRL). This could allow a network-based attacker to establish a connection using a certificate that should be untrusted, potentially bypassing CIP Security protections.

EPSS

Процентиль: 4%
0.0014
Низкий

Дефекты

CWE-299

Связанные уязвимости

github
17 дней назад

A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate revocation handling. The security issue stems from the controller failing to properly reject certificates signed by an intermediate certificate that has been revoked via a Certificate Revocation List (CRL). This could allow a network-based attacker to establish a connection using a certificate that should be untrusted, potentially bypassing CIP Security protections.

CVSS3: 5.9
fstec
18 дней назад

Уязвимость функции Certificate Revocation List (CRL) микропрограммного обеспечения программируемых логических контроллеров Rockwell Automation ControlLogix 5580, GuardLogix 5580, CompactLogix 5380 и Compact GuardLogix 5380, позволяющая нарушителю обойти ограничения безопасности

EPSS

Процентиль: 4%
0.0014
Низкий

Дефекты

CWE-299