CVE-2019-10955
Summary
| CVE | CVE-2019-10955 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-25 18:29:00 UTC |
| Updated | 2026-06-03 14:16:20 UTC |
| Description | In Rockwell Automation MicroLogix 1400 Controllers Series A, All Versions Series B, v15.002 and earlier, MicroLogix 1100 Controllers v14.00 and earlier, CompactLogix 5370 L1 controllers v30.014 and earlier, CompactLogix 5370 L2 controllers v30.014 and earlier, CompactLogix 5370 L3 controllers (includes CompactLogix GuardLogix controllers) v30.014 and earlier, an open redirect vulnerability could allow a remote unauthenticated attacker to input a malicious link to redirect users to a malicious site that could run or download arbitrary malware on the user’s machine. |
Risk And Classification
Primary CVSS: v3.1 6.1 MEDIUM from ADP
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Problem Types: CWE-601 | CWE-601 URL REDIRECTION TO UNTRUSTED SITE ('OPEN REDIRECT') CWE-601
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ADP | DECLARED | 6.1 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 6.1 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
| 3.0 | [email protected] | Primary | 6.1 | MEDIUM | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
| 2.0 | [email protected] | Primary | 5.8 | AV:N/AC:M/Au:N/C:P/I:P/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
ChangedConfidentiality
LowIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
ChangedConfidentiality
LowIntegrity
LowAvailability
NoneCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Rockwellautomation | Compactlogix 5370 L1 | - | All | All | All |
| Operating System | Rockwellautomation | Compactlogix 5370 L1 Firmware | All | All | All | All |
| Hardware | Rockwellautomation | Compactlogix 5370 L2 | - | All | All | All |
| Operating System | Rockwellautomation | Compactlogix 5370 L2 Firmware | All | All | All | All |
| Hardware | Rockwellautomation | Compactlogix 5370 L3 | - | All | All | All |
| Operating System | Rockwellautomation | Compactlogix 5370 L3 Firmware | All | All | All | All |
| Hardware | Rockwellautomation | Micrologix 1100 | - | All | All | All |
| Operating System | Rockwellautomation | Micrologix 1100 Firmware | All | All | All | All |
| Hardware | Rockwellautomation | Micrologix 1400 | - | All | All | All |
| Operating System | Rockwellautomation | Micrologix 1400 A Firmware | All | All | All | All |
| Operating System | Rockwellautomation | Micrologix 1400 B Firmware | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Rockwell Automation | MicroLogix 1400 Controllers | affected Series A | Not specified |
| CNA | Rockwell Automation | MicroLogix 1400 Controllers | affected All Versions Series B | Not specified |
| CNA | Rockwell Automation | MicroLogix 1400 Controllers | affected v15.002 and earlier | Not specified |
| CNA | Rockwell Automation | MicroLogix 1100 Controllers | affected v14.00 and earlier | Not specified |
| CNA | Rockwell Automation | CompactLogix 5370 L1 Controllers | affected v30.014 and earlier | Not specified |
| CNA | Rockwell Automation | CompactLogix 5370 L2 Controllers | affected v30.014 and earlier | Not specified |
| CNA | Rockwell Automation | CompactLogix 5370 L3 Controllers | affected v30.014 and earlier | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Rockwell Automation MicroLogix 1400 and CompactLogix 5370 Controllers Open Redirection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Rockwell Automation MicroLogix 1400 and CompactLogix 5370 Controllers | ICS-CERT | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.