CVE-2023-2262 - CVE House
Back to Database
Status published Critical CVE-2023-2262

Rockwell Automation Select Logix Communication Modules Vulnerable to Email Object Buffer Overflow

Vulnerability Description

A buffer overflow vulnerability exists in the Rockwell Automation select 1756-EN* communication devices. If exploited, a threat actor could potentially leverage this vulnerability to perform a remote code execution. To exploit this vulnerability, a threat actor would have to send a maliciously crafted CIP request to device.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-2262

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Rockwell Automation

View all reports →

Affected Software

1756-EN2T Series A, B, C, 1756-EN2T Series D, 1756-EN2TK Series A, B, C, 1756-EN2TXT Series A, B, C, 1756-EN2TXT Series D, 1756-EN2TP Series A, 1756-EN2TPK Series A, 1756-EN2TPXT Series A, 1756-EN2TR Series A, B, 1756-EN2TR Series C, 1756-EN2TRK Series A, B, 1756-EN2TRK Series C, 1756-EN2TRXT Series A, B, 1756-EN2TRXT Series C, 1756-EN2F Series A, B, 1756-EN2F Series C, 1756-EN2FK Series A, B, 1756-EN2FK Series C, 1756-EN3TR Series A, 1756-EN3TR Series B, 1756-EN3TRK Series A, 1756-EN3TRK Series B
Vulnerable Versions:
<=5.008 & 5.028, <=11.002, <=11.003

Timeline

Official Publish: September 20th, 2023
Last Modified: September 25th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)