CVE-2010-5305
Summary
| CVE | CVE-2010-5305 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-03-26 18:29:00 UTC |
| Updated | 2020-02-10 21:19:00 UTC |
| Description | The potential exists for exposure of the product's password used to restrict unauthorized access to Rockwell PLC5/SLC5/0x/RSLogix 1785-Lx and 1747-L5x controllers. The potential exists for an unauthorized programming and configuration client to gain access to the product and allow changes to the product’s configuration or program. When applicable, upgrade product firmware to a version that includes enhanced security functionality compatible with Rockwell Automation's FactoryTalk Security services. |
Risk And Classification
Problem Types: CWE-284
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Rockwellautomation | Plc5 1785-lx | - | All | All | All |
| Hardware | Rockwellautomation | Plc5 1785-lx | - | All | All | All |
| Operating System | Rockwellautomation | Plc5 1785-lx Firmware | - | All | All | All |
| Operating System | Rockwellautomation | Plc5 1785-lx Firmware | - | All | All | All |
| Application | Rockwellautomation | Rslogix | All | All | All | All |
| Application | Rockwellautomation | Rslogix | All | All | All | All |
| Hardware | Rockwellautomation | Slc5/01 1747-l5x | - | All | All | All |
| Operating System | Rockwellautomation | Slc5/01 1747-l5x Firmware | - | All | All | All |
| Hardware | Rockwellautomation | Slc5/01 1747-l5x | - | All | All | All |
| Hardware | Rockwellautomation | Slc5/01 1747-l5x | - | All | All | All |
| Operating System | Rockwellautomation | Slc5/01 1747-l5x Firmware | - | All | All | All |
| Operating System | Rockwellautomation | Slc5/01 1747-l5x Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Rockwell PLC5/SLC5/0x/RSLogix Security Vulnerability | ICS-CERT | MISC | ics-cert.us-cert.gov | Mitigation, Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.