CVE-2009-0473
Open redirect vulnerability in the web interface in the Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge Module allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.2%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Open redirect vulnerability in the web interface in the Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge Module allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 13.22% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-59
- Affected
- rockwellautomation/controllogix 1756-enbt\/a ethernet\/ ip bridge
- Source
- cve@mitre.org
References
- http://rockwellautomation.custhelp.com/cgi-bin/rockwellautomation.cfg/php/enduser/std_adp.php?p_faqid=57729Vendor Advisory
- http://secunia.com/advisories/33783
- http://www.kb.cert.org/vuls/id/619499US Government Resource
- http://www.securityfocus.com/bid/33636
- http://www.vupen.com/english/advisories/2009/0347
- http://rockwellautomation.custhelp.com/cgi-bin/rockwellautomation.cfg/php/enduser/std_adp.php?p_faqid=57729Vendor Advisory
- http://secunia.com/advisories/33783
- http://www.kb.cert.org/vuls/id/619499US Government Resource
- http://www.securityfocus.com/bid/33636
- http://www.vupen.com/english/advisories/2009/0347
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.