Rockwell Automation Stratix 5410
cpe:2.3:h:rockwellautomation:allen-bradley_stratix_5410:*:*:*:*:*:*:*
- <= 15.2(8)E5
A cross-site request forgery vulnerability has been identified in Rockwell Automation Stratix IOS devices, specifically in the Stratix 5410, 5700, and 8000 series. This vulnerability allows for remote code execution by uploading and executing malicious configurations without authentication. The issue arises from improper handling of cross-site request forgery, enabling unauthorized actions to be performed on behalf of a user.
Exploitation of this vulnerability could lead to unauthorized remote code execution on the affected Stratix IOS devices.
Users can upgrade to Stratix IOS version 15.2(8)E6 to address this vulnerability. For those unable to upgrade, Rockwell Automation recommends following their security best practices.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.