Количество 3
Количество 3
CVE-2022-46670
Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology that the MicroLogix 1100 and 1400 controllers contain a vulnerability that may give an attacker the ability to accomplish remote code execution. The vulnerability is an unauthenticated stored cross-site scripting vulnerability in the embedded webserver. The payload is transferred to the controller over SNMP and is rendered on the homepage of the embedded website.
GHSA-x7wf-5vvq-hf3f
Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology that the MicroLogix 1100 and 1400 controllers contain a vulnerability that may give an attacker the ability to accomplish remote code execution. The vulnerability is an unauthenticated stored cross-site scripting vulnerability in the embedded webserver. The payload is transferred to the controller over SNMP and is rendered on the homepage of the embedded website.
BDU:2025-05556
Уязвимость встроенного веб-сервера микропрограммного обеспечения программируемых логических контроллеров Rockwell Automation Micrologix 1100 и 1400, позволяющая нарушителю проводить межсайтовые сценарные атаки
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-46670 Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology that the MicroLogix 1100 and 1400 controllers contain a vulnerability that may give an attacker the ability to accomplish remote code execution. The vulnerability is an unauthenticated stored cross-site scripting vulnerability in the embedded webserver. The payload is transferred to the controller over SNMP and is rendered on the homepage of the embedded website. | CVSS3: 7.1 | 0% Низкий | около 3 лет назад | |
GHSA-x7wf-5vvq-hf3f Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology that the MicroLogix 1100 and 1400 controllers contain a vulnerability that may give an attacker the ability to accomplish remote code execution. The vulnerability is an unauthenticated stored cross-site scripting vulnerability in the embedded webserver. The payload is transferred to the controller over SNMP and is rendered on the homepage of the embedded website. | CVSS3: 6.1 | 0% Низкий | около 3 лет назад | |
BDU:2025-05556 Уязвимость встроенного веб-сервера микропрограммного обеспечения программируемых логических контроллеров Rockwell Automation Micrologix 1100 и 1400, позволяющая нарушителю проводить межсайтовые сценарные атаки | CVSS3: 7.1 | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу