CVE-2023-3595

CRITICALCVSS 9.8/10EPSS 3.64%

Last modified

CVE-2023-3595 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Where this vulnerability exists in the Rockwell Automation 1756 EN2* and 1756 EN3* ControlLogix communication products, it could allow a malicious user to perform remote code execution with persistence on the target system through maliciously crafted CIP messages. This includes the ability to modify, deny, and exfiltrate data passing through the device. . EPSS estimates a 3.64% chance of exploitation in the next 30 days.

Description

Where this vulnerability exists in the Rockwell Automation 1756 EN2* and 1756 EN3* ControlLogix communication products, it could allow a malicious user to perform remote code execution with persistence on the target system through maliciously crafted CIP messages. This includes the ability to modify, deny, and exfiltrate data passing through the device.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
3.64%

88.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Rockwellautomation1756-En2f Series A FirmwareAll versions
Rockwellautomation1756-En2f Series B FirmwareAll versions
Rockwellautomation1756-En2f Series C FirmwareAll versions
Rockwellautomation1756-En2t Series A FirmwareAll versions
Rockwellautomation1756-En2t Series B FirmwareAll versions
Rockwellautomation1756-En2t Series C FirmwareAll versions
Rockwellautomation1756-En2t Series D FirmwareAll versions
Rockwellautomation1756-En2tr Series A FirmwareAll versions
Rockwellautomation1756-En2tr Series B FirmwareAll versions
Rockwellautomation1756-En2tr Series C FirmwareAll versions
Rockwellautomation1756-En3tr Series A FirmwareAll versions
Rockwellautomation1756-En3tr Series B FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2023-3595?
Where this vulnerability exists in the Rockwell Automation 1756 EN2* and 1756 EN3* ControlLogix communication products, it could allow a malicious user to perform remote code execution with persistence on the target system through maliciously crafted CIP messages. This includes the ability to modify, deny, and exfiltrate data passing through the device.
How severe is CVE-2023-3595?
CVE-2023-3595 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 3.64% probability of exploitation in the next 30 days.
How do I fix CVE-2023-3595?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2023-3595?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST