peter bassill · operator
$ cve CVE-2019-10952 JSON

CVE-2019-10952

9.8
CRITICAL · CVSS 3.1 · EPSS 10% (pctl 95)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An attacker could send a crafted HTTP/HTTPS request to render the web server unavailable and/or lead to remote code execution caused by a stack-based buffer overflow vulnerability. A cold restart is required for recovering CompactLogix 5370 L1, L2, and L3 Controllers, Compact GuardLogix 5370 controllers, and Armor Compact GuardLogix 5370 Controllers Versions 20 - 30 and earlier.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS9.99% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-400
On CISA KEVno
Public exploitnone known
Published2019-05-01
Last modified2026-06-17

Affected (8)

VendorProduct
rockwellautomationarmor compact guardlogix 5370
rockwellautomationarmor compact guardlogix 5370 firmware
rockwellautomationcompactlogix 5370 l1
rockwellautomationcompactlogix 5370 l1 firmware
rockwellautomationcompactlogix 5370 l2
rockwellautomationcompactlogix 5370 l2 firmware
rockwellautomationcompactlogix 5370 l3
rockwellautomationcompactlogix 5370 l3 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD