CVE-2023-0027
Published on: Not Yet Published
Last Modified on: 03/20/2023 02:46:00 AM UTC
Certain versions of Modbus TCP Server Add On Instructions from Rockwell Automation contain the following vulnerability:
Rockwell Automation Modbus TCP Server AOI prior to 2.04.00 is vulnerable to an unauthorized user sending a malformed message that could cause the controller to respond with a copy of the most recent response to the last valid request. If exploited, an unauthorized user could read the connected device’s Modbus TCP Server AOI information.
- CVE-2023-0027 has been assigned by
[email protected] to track the vulnerability
- Affected Vendor/Software:
Rockwell Automation - Modbus TCP Server Add On Instructions version = 2.00.00 - 2.00.03
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Modbus TCP AOI Server Could Leak Sensitive Information | rockwellautomation.custhelp.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Software
Vendor | Product | Version |
---|---|---|
Rockwell Automation | Modbus_TCP_Server_Add_On_Instructions | = 2.00.00 - 2.00.03 |
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-0027 : Rockwell Automation Modbus TCP Server AOI prior to 2.04.00 is vulnerable to an unauthorized user se… twitter.com/i/web/status/1… | 2023-03-17 17:01:36 |