CVE-2019-10970
In Rockwell Automation PanelView 5510 (all versions manufactured before March 13, 2019 that have never been updated to v4.003, v5.002, or later), a remote, unauthenticated threat actor with access to an affected PanelView 5510 Graphic Display, upon…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.60%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In Rockwell Automation PanelView 5510 (all versions manufactured before March 13, 2019 that have never been updated to v4.003, v5.002, or later), a remote, unauthenticated threat actor with access to an affected PanelView 5510 Graphic Display, upon successful exploit, may boot-up the terminal and gain root-level access to the device’s file system.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.60% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- rockwellautomation/panelview 5510 firmware
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/109105Third Party Advisory, VDB Entry
- https://www.us-cert.gov/ics/advisories/icsa-19-190-02Mitigation, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/109105Third Party Advisory, VDB Entry
- https://www.us-cert.gov/ics/advisories/icsa-19-190-02Mitigation, Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.