CVE Feed

    Dashboard / CVE / CVE-2023-2423

    CVE-2023-2423

    A vulnerability was discovered in the Rockwell Automation Armor PowerFlex device when the product sends communications to the local event log. Threat actors could exploit this vulnerability by sending an influx of network commands, causing the product to generate an influx of event log traffic at a high rate. If exploited, the product would stop normal operations and self-reset creating a denial-of-service condition. The error code would need to be cleared prior to resuming normal operations.

    Published:Aug 8, 2023
    Last Modified:Nov 21, 2024
    EPS:Aug 8, 2023
    EPSS Score:0.0005
    CVSS Score:8.6

    Affected Products

    Vendor
    Rockwellautomation
    Product
    Armor Powerflex
    Vendor
    Rockwellautomation
    Product
    Armor Powerflex Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High