CVE-2026-9307
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
16/06/2026
Last modified:
16/06/2026
Description
A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Connection IDs on the diagnostics webpage, which are accessible to any unauthenticated user on the network. This information can be leveraged by an attacker to construct malicious packets, leading to Denial-of-Service.
Impact
Base Score 4.0
6.30
Severity 4.0
MEDIUM



