Critical severity9.8NVD Advisory· Published May 1, 2019· Updated Jun 17, 2026
CVE-2019-10952
CVE-2019-10952
Description
An attacker could send a crafted HTTP/HTTPS request to render the web server unavailable and/or lead to remote code execution caused by a stack-based buffer overflow vulnerability. A cold restart is required for recovering
CompactLogix 5370 L1, L2, and L3 Controllers, Compact GuardLogix 5370 controllers, and Armor Compact GuardLogix 5370 Controllers Versions 20 - 30 and earlier.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11- cpe:2.3:o:rockwellautomation:armor_compact_guardlogix_5370_firmware:*:*:*:*:*:*:*:*Range: >=20.011,<=30.014
- cpe:2.3:o:rockwellautomation:compactlogix_5370_l1_firmware:*:*:*:*:*:*:*:*Range: >=20.011,<=30.014
- cpe:2.3:o:rockwellautomation:compactlogix_5370_l2_firmware:*:*:*:*:*:*:*:*Range: >=20.011,<=30.014
- cpe:2.3:o:rockwellautomation:compactlogix_5370_l3_firmware:*:*:*:*:*:*:*:*Range: >=20.011,<=30.014
- Range: <=20, 30
- Range: <=20, 30
0+ 1 more
- (no CPE)range: 0
- (no CPE)range: 0
0+ 2 more
- (no CPE)range: 0
- (no CPE)range: 0
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
3- www.securityfocus.com/bid/108118nvdThird Party AdvisoryVDB Entry
- ics-cert.us-cert.gov/advisories/ICSA-19-120-01nvdThird Party AdvisoryUS Government Resource
- rockwellautomation.custhelp.com/app/answers/detail/a_id/1075979nvd
News mentions
0No linked articles in our index yet.