First published: Fri Feb 06 2009(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the web interface in the Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge Module allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Rockwellautomation Controllogix 1756-enbt\/a Ethernet\/ Ip Bridge |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0472 has been assigned a moderate severity rating due to the potential for cross-site scripting attacks.
To fix CVE-2009-0472, ensure you apply the latest security patches provided by Rockwell Automation for the affected ControlLogix 1756-ENBT/A EtherNet/IP Bridge Module.
The impacts of CVE-2009-0472 include the possibility of remote attackers injecting malicious scripts into the web interface, potentially compromising the confidentiality and integrity of user data.
Yes, CVE-2009-0472 is exploitable remotely as it allows attackers to target the web interface of the affected device.
CVE-2009-0472 affects all versions of the ControlLogix 1756-ENBT/A EtherNet/IP Bridge Module that are using unpatched firmware.