← Vulnerability feed

Vulnerability record · CVE-2019-10955 · published 25 April 2019

CVE-2019-10955: Rockwellautomation micrologix 1400 a firmware open redirect vulnerability

Rockwellautomation · Micrologix 1400 A Firmware

In Rockwell Automation MicroLogix 1400 Controllers Series A, All Versions Series B, v15.002 and earlier, MicroLogix 1100 Controllers v14.00 and earlier, CompactLogix 5370 L1 controllers v30.014 and earlier, CompactLogix 5370 L2 controllers v30.014 and earlier, CompactLogix 5370 L3 controllers (includes CompactLogix GuardLogix controllers) v30.014 and earlier, an open redirect vulnerability could allow a remote unauthenticated attacker to input a malicious link to redirect users to a malicious site that could run or download arbitrary malware on the user’s machine.

6.1 CVSS 3.1 Medium EPSS 3.1% · top 12.9% CWE-601 · Open redirect
6.1CVSS 3.1 base score, v2 5.8
3.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

In Rockwell Automation MicroLogix 1400 Controllers Series A, All Versions Series B, v15.002 and earlier, MicroLogix 1100 Controllers v14.00 and earlier, CompactLogix 5370 L1 controllers v30.014 and earlier, CompactLogix 5370 L2 controllers v30.014 and earlier, CompactLogix 5370 L3 controllers (includes CompactLogix GuardLogix controllers) v30.014 and earlier, an open redirect vulnerability could allow a remote unauthenticated attacker to input a malicious link to redirect users to a malicious site that could run or download arbitrary malware on the user’s machine.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://ics-cert.us-cert.gov/advisories/ICSA-19-113-01 Third Party AdvisoryUS Government Resource
https://www.securityfocus.com/bid/108049 Third Party AdvisoryVDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-19-113-01 Third Party AdvisoryUS Government Resource
https://www.securityfocus.com/bid/108049 Third Party AdvisoryVDB Entry

Track CVE-2019-10955 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-1161Rockwellautomation compactlogix 1768-l43 firmware inclusion from untrusted sphere vulnerabilityAn attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems…EPSS 5.2%9.8CVE-2020-6990Rockwellautomation micrologix 1400 a firmware hard-coded credentials vulnerabilityRockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix…EPSS 4.4%9.8CVE-2019-10952Rockwellautomation compactlogix 5370 l1 firmware uncontrolled resource consumption vulnerabilityAn attacker could send a crafted HTTP/HTTPS request to render the web server unavailable and/or lead to remote code execution caused by a stack-based…EPSS 10.0%9.8CVE-2015-6490Rockwellautomation micrologix 1100 firmware memory buffer overflow vulnerabilityStack-based buffer overflow on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices through B FRN 15.003 allows remote attacker…EPSS 7.0%8.6CVE-2020-6998Rockwellautomation armor compact guardlogix 5370 firmware improper input validation vulnerabilityThe connection establishment algorithm found in Rockwell Automation CompactLogix 5370 and ControlLogix 5570 versions 33 and prior does not sufficient…EPSS 2.3%8.6CVE-2021-33012Rockwellautomation micrologix 1100 firmware improper input validation vulnerabilityRockwell Automation MicroLogix 1100, all versions, allows a remote, unauthenticated attacker sending specially crafted commands to cause the PLC to f…EPSS 2.6%7.5CVE-2022-3166Rockwellautomation micrologix 1100 firmware vulnerabilityRockwell Automation was made aware that the webservers of the Micrologix 1100 and 1400 controllers contain a vulnerability that may lead to a denial-…EPSS 0.70%7.5CVE-2020-6984Rockwellautomation micrologix 1400 a firmware broken cryptographic algorithm vulnerabilityRockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix…EPSS 2.8%

Source: NIST National Vulnerability Database (record CVE-2019-10955), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.