SEPTEMBER 24, 2026
Live Feed
Back to database
Case File

CVE-2026-9307

UNKNOWN · CVSS N/A EPSS 0.30%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-06-16 · Last synced 2026-08-04

CyberRota Analysis

This vulnerability has an unknown severity rating. Exploitation may require the attacker to be authenticated. It may lead to a denial-of-service condition.

CVE
CVE-2026-9307
Severity
UNKNOWN
CVSS
N/A
EPSS
0.30%

Original NVD Description

A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Connection IDs on the diagnostics webpage, which are accessible to any unauthenticated user on the network. This information can be leveraged by an attacker to construct malicious packets, leading to Denial-of-Service.