{"api_version":"1","generated_at":"2026-07-23T20:19:09+00:00","cve":"CVE-2023-1834","urls":{"html":"https://cve.report/CVE-2023-1834","api":"https://cve.report/api/cve/CVE-2023-1834.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-1834","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-1834"},"summary":{"title":"CVE-2023-1834","description":"Rockwell Automation was made aware that Kinetix 5500 drives, manufactured between May 2022 and January 2023, and are running v7.13 may have the telnet and FTP ports open by default.  This could potentially allow attackers unauthorized access to the device through the open ports.","state":"PUBLIC","assigner":"PSIRT@rockwellautomation.com","published_at":"2023-05-11 19:15:00","updated_at":"2023-05-22 18:17:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1139441","name":"https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1139441","refsource":"MISC","tags":[],"title":"Open Ports Vulnerability in Kinetix 5500 EtherNet/IP Servo Drive","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-23-131-09","name":"https://www.cisa.gov/news-events/ics-advisories/icsa-23-131-09","refsource":"MISC","tags":["Third Party Advisory","US Government Resource"],"title":"Rockwell Automation Kinetix 5500 | CISA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-1834","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-1834","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"1834","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"rockwellautomation","cpe5":"kinetix_5500","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"1834","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"rockwellautomation","cpe5":"kinetix_5500_firmware","cpe6":"7.13","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-1834","ASSIGNER":"PSIRT@rockwellautomation.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"\nRockwell Automation was made aware that Kinetix 5500 drives, manufactured between May 2022 and January 2023, and are running v7.13 may have the telnet and FTP ports open by default.  This could potentially allow attackers unauthorized access to the device through the open ports."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-284 Improper Access Control","cweId":"CWE-284"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Rockwell Automation","product":{"product_data":[{"product_name":"Kinetix 5500 EtherNet/IP Servo Drive","version":{"version_data":[{"version_affected":"=","version_value":"7.13"}]}}]}}]}},"references":{"reference_data":[{"url":"https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1139441","refsource":"MISC","name":"https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1139441"}]},"generator":{"engine":"Vulnogram 0.1.0-dev"},"source":{"discovery":"UNKNOWN"},"solution":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Customers should upgrade to v7.14 to correct the issue."}],"value":"Customers should upgrade to v7.14 to correct the issue."}],"impact":{"cvss":[{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.4,"baseSeverity":"CRITICAL","confidentialityImpact":"LOW","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H","version":"3.1"}]}},"nvd":{"publishedDate":"2023-05-11 19:15:00","lastModifiedDate":"2023-05-22 18:17:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.2}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:rockwellautomation:kinetix_5500_firmware:7.13:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:h:rockwellautomation:kinetix_5500:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":null,"notes":[]}}}