Compactlogix
Vendor:
First CVE: Jan 24, 2013 · Active for 13 years
7
Total CVEs
More Total CVEs than 85% of tracked products
7.0
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Compactlogix over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 24, 2013
13 years ago
Most Recent CVE
Jan 24, 2013
4,933 days ago
CVE Severity & Scoring
Compactlogix7 CVEs
29%
57%
14%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network5 (71.4%)
Unknown2 (28.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (57.1%)
High1 (14.3%)
Unknown2 (28.6%)
User Interaction
None5 (71.4%)
Unknown2 (28.6%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None5 (71.4%)
Unknown2 (28.6%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-6441MEDIUM An information exposure of confidential information results when the device receives a specially crafted CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/U | Jan 24, 2013 | 5.0 | 43 | NO | NO |
CVE-2012-6435HIGH When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that instructs th | Jan 24, 2013 | 7.5 | 43 | NO | NO |
CVE-2012-6438HIGH The device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/ | Jan 24, 2013 | 7.5 | 38 | NO | NO |
CVE-2012-6439HIGH When an affected
product receives a valid CIP message from an unauthorized or unintended
source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port
44818/UDP that changes t | Jan 24, 2013 | 8.5 | 37 | NO | NO |
CVE-2012-6436HIGH The device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/ | Jan 24, 2013 | 7.5 | 37 | NO | NO |
CVE-2012-6437CRITICAL The device does not properly authenticate users and the potential exists for a remote user to upload a new firmware image to the Ethernet card, whether it is a corrupt or legitimat | Jan 24, 2013 | 9.8 | 32 | NO | NO |
CVE-2012-6440MEDIUM The Web server password authentication mechanism used by the products is vulnerable to a MitM and Replay attack. Successful exploitation of this vulnerability will allow unauthoriz | Jan 24, 2013 | 4.8 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Compactlogix
Top CWEs
Versions
No cataloged versions.