peter bassill · operator
$ cve CVE-2010-5305 JSON

CVE-2010-5305

9.8
CRITICAL · CVSS 3.0 · EPSS 5.7% (pctl 93)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The potential exists for exposure of the product's password used to restrict unauthorized access to Rockwell PLC5/SLC5/0x/RSLogix 1785-Lx and 1747-L5x controllers. The potential exists for an unauthorized programming and configuration client to gain access to the product and allow changes to the product’s configuration or program. When applicable, upgrade product firmware to a version that includes enhanced security functionality compatible with Rockwell Automation's FactoryTalk Security services.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.7% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-255
On CISA KEVno
Public exploitnone known
Published2019-03-26
Last modified2026-06-16

Affected (5)

VendorProduct
rockwellautomationplc5 1785-lx
rockwellautomationplc5 1785-lx firmware
rockwellautomationrslogix
rockwellautomationslc5\/01 1747-l5x
rockwellautomationslc5\/01 1747-l5x firmware

References

→ the Explorer  ·  watch your stack  ·  NVD