CVE-2019-10952 is a critical stack-based buffer overflow vulnerability affecting Rockwell Automation CompactLogix 5370 L1, L2, L3, Compact GuardLogix 5370, and Armor Compact GuardLogix 5370 controllers running firmware versions 20-30 and earlier. An unauthenticated attacker can exploit this flaw by sending a crafted HTTP/HTTPS request, leading to a denial-of-service (DoS) condition requiring a cold restart, or potentially remote code execution. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network with low attack complexity and no user interaction, resulting in high impacts to confidentiality, integrity, and availability. While there is no evidence of active exploitation or publicly available exploit code in Metasploit or ExploitDB, the vulnerability has received limited community discussion and media coverage, indicating a lower but still present risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 20.011, <= 30.014CPE matchmatch criteria | cpe:2.3:o:rockwellautomation:compactlogix_5370_l1_firmware:*:*:*:*:*:*:*:* | ||
>= 20.011, <= 30.014CPE matchmatch criteria | cpe:2.3:o:rockwellautomation:compactlogix_5370_l2_firmware:*:*:*:*:*:*:*:* | ||
>= 20.011, <= 30.014CPE matchmatch criteria | cpe:2.3:o:rockwellautomation:compactlogix_5370_l3_firmware:*:*:*:*:*:*:*:* | ||
>= 20.011, <= 30.014CPE matchmatch criteria | cpe:2.3:o:rockwellautomation:armor_compact_guardlogix_5370_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.