CVE 9.9 CRITICAL

Rockwell Automation Comms – 1783-NATR Multiple Broken Authentication Vulnerabilities_CVE-2025-7328

9.9 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:H

Description

Multiple Broken Authentication security issues exist in the affected product. The security issues are due to missing authentication checks on critical functions. These could result in potential denial-of-service, admin account takeover, or NAT rule modifications. Devices would no longer be able to communicate through NATR as a result of denial-of-service or NAT rule modifications. NAT rule modification could also result in device communication to incorrect endpoints. Admin account takeover could allow modification of configuration and require physical access to restore.

AI Analysis

AI processing failed - returned non-JSON response

Basic Information

ID CVE-2025-7328
Source Rockwell
Published Oct 14, 2025 at 12:35
Modified Oct 14, 2025 at 13:22

Affected Product

Vendor Rockwell Automation
Product Comms - 1783-NATR
Version Version 1.006 and prior
Affected Versions Rockwell Automation Comms - 1783-NATR Version 1.006 and prior

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.