Vulnerabilities > Rockwellautomation > 1756 En3Tr Series B Firmware

DATE CVE VULNERABILITY TITLE RISK
2023-09-20 CVE-2023-2262 Out-of-bounds Write vulnerability in Rockwellautomation products
A buffer overflow vulnerability exists in the Rockwell Automation select 1756-EN* communication devices.
network
low complexity
rockwellautomation CWE-787
critical
9.8
2023-07-12 CVE-2023-3595 Out-of-bounds Write vulnerability in Rockwellautomation products
Where this vulnerability exists in the Rockwell Automation 1756 EN2* and 1756 EN3* ControlLogix communication products, it could allow a malicious user to perform remote code execution with persistence on the target system through maliciously crafted CIP messages.
network
low complexity
rockwellautomation CWE-787
critical
9.8
2018-12-07 CVE-2018-17924 Missing Authentication for Critical Function vulnerability in Rockwellautomation products
Rockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unauthenticated, remote threat actor could send a CIP connection request to an affected device, and upon successful connection, send a new IP configuration to the affected device even if the controller in the system is set to Hard RUN mode.
network
low complexity
rockwellautomation CWE-306
7.8