CyberRota Analysis
This vulnerability has an unknown severity rating. Exploitation may require the attacker to be authenticated. It may lead to a denial-of-service condition.
CVE
CVE-2026-9307
Severity
UNKNOWN
CVSS
N/A
EPSS
0.30%
Original NVD Description
A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Connection IDs on the diagnostics webpage, which are accessible to any unauthenticated user on the network. This information can be leveraged by an attacker to construct malicious packets, leading to Denial-of-Service.