CVE-2023-3596

Where this vulnerability exists in the Rockwell Automation 1756-EN4* Ethernet/IP communication products, it could allow a malicious user to cause a denial of service by asserting the target system through maliciously crafted CIP messages.
References
Link Resource
https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1140010 Permissions Required Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:rockwellautomation:1756-en4tr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:1756-en4tr:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:rockwellautomation:1756-en4trk_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:1756-en4trk:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:rockwellautomation:1756-en4trxt_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:1756-en4trxt:-:*:*:*:*:*:*:*

History

20 Jul 2023, 19:51

Type Values Removed Values Added
CPE cpe:2.3:o:rockwellautomation:1756-en4tr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:1756-en4trk:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:1756-en4trk_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:1756-en4trxt_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:1756-en4trxt:-:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:1756-en4tr:-:*:*:*:*:*:*:*
CWE CWE-787
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References (MISC) https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1140010 - (MISC) https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1140010 - Permissions Required, Vendor Advisory

12 Jul 2023, 13:56

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-12 13:15

Updated : 2024-02-05 00:01


NVD link : CVE-2023-3596

Mitre link : CVE-2023-3596

CVE.ORG link : CVE-2023-3596


JSON object : View

Products Affected

rockwellautomation

  • 1756-en4tr_firmware
  • 1756-en4tr
  • 1756-en4trk
  • 1756-en4trk_firmware
  • 1756-en4trxt
  • 1756-en4trxt_firmware
CWE
CWE-787

Out-of-bounds Write