CVE-2023-1834: Rockwell Automation Kinetix 5500 Vulnerable to Open Port Exploitation
Rockwell Automation was made aware that Kinetix 5500 drives, manufactured between May 2022 and January 2023, and are running v7.13 may have the telnet and FTP ports open by default. This could potentially allow attackers unauthorized access to the device through the open ports.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-1834?
CVE-2023-1834 is a vulnerability in Rockwell Automation Kinetix 5500 drives running v7.13 firmware, where the telnet and FTP ports may be open by default, allowing unauthorized access.
How severe is CVE-2023-1834?
CVE-2023-1834 has a severity rating of 9.1 (critical).
Are all Kinetix 5500 drives affected by CVE-2023-1834?
No, only Kinetix 5500 drives running v7.13 firmware are affected by CVE-2023-1834.
How can unauthorized access be prevented for Kinetix 5500 drives affected by CVE-2023-1834?
To prevent unauthorized access, Rockwell Automation recommends disabling telnet and FTP ports or upgrading to a version of firmware that does not have these ports open.
Where can I find more information about CVE-2023-1834?
More information about CVE-2023-1834 can be found on the Rockwell Automation and CISA websites.