Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 26 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rockwellautomation
Rockwellautomation flex I/o Ethernet/ip Adapter |
|
| Vendors & Products |
Rockwellautomation
Rockwellautomation flex I/o Ethernet/ip Adapter |
Tue, 16 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 16 Jun 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper authentication security issue exists within the 1794-AENTR adapter's embedded web server. The vulnerability allows an unauthenticated attacker to change the device's web interface password by sending a crafted HTTP GET request to a specific endpoint, without any prior authentication being required. If exploited, this could lead to unauthorized access, account takeover, and loss of the device’s embedded web server’s availability. | |
| Title | Rockwell Automation FLEX I/O Dual-port EtherNet/IP Adapters – Multiple Vulnerabilities | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Rockwell
Published:
Updated: 2026-06-16T15:23:45.399Z
Reserved: 2026-01-06T16:09:07.074Z
Link: CVE-2026-0647
Updated: 2026-06-16T15:23:41.948Z
Status : Awaiting Analysis
Published: 2026-06-16T15:16:33.687
Modified: 2026-06-16T15:26:04.250
Link: CVE-2026-0647
No data.
OpenCVE Enrichment
Updated: 2026-06-26T09:45:17Z