Medium severity5.3NVD Advisory· Published Feb 24, 2022· Updated Jun 17, 2026
CVE-2020-14504
CVE-2020-14504
Description
The web interface of the 1734-AENTR communication module mishandles authentication for HTTP POST requests. A remote, unauthenticated attacker can send a crafted request that may allow for modification of the configuration settings.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- cpe:2.3:o:rockwellautomation:1734-aentr_point_i\/o_dual_port_network_adaptor_series_b_firmware:*:*:*:*:*:*:*:*Range: >=4.001,<=4.005
cpe:2.3:o:rockwellautomation:1734-aentr_point_i\/o_dual_port_network_adaptor_series_c_firmware:6.011:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:rockwellautomation:1734-aentr_point_i\/o_dual_port_network_adaptor_series_c_firmware:6.011:*:*:*:*:*:*:*
- cpe:2.3:o:rockwellautomation:1734-aentr_point_i\/o_dual_port_network_adaptor_series_c_firmware:6.012:*:*:*:*:*:*:*
- Range: Series B 4.001 to 4.005, and 5.011 to 5.017
Patches
Vulnerability mechanics
References
1- www.cisa.gov/uscert/ics/advisories/icsa-21-063-01nvdMitigationThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.