CVE-2023-1834
Summary
| CVE | CVE-2023-1834 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-05-11 19:15:00 UTC |
| Updated | 2023-05-22 18:17:00 UTC |
| Description | Rockwell Automation was made aware that Kinetix 5500 drives, manufactured between May 2022 and January 2023, and are running v7.13 may have the telnet and FTP ports open by default. This could potentially allow attackers unauthorized access to the device through the open ports. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Rockwellautomation | Kinetix 5500 | - | All | All | All |
| Operating System | Rockwellautomation | Kinetix 5500 Firmware | 7.13 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Open Ports Vulnerability in Kinetix 5500 EtherNet/IP Servo Drive | MISC | rockwellautomation.custhelp.com | |
| Rockwell Automation Kinetix 5500 | CISA | MISC | www.cisa.gov | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.