CVE-2023-0027: Rockwellautomation Modbus TCP Server Add On Instructions

Medium severity, CVSS 4.3. EPSS: 0.8% chance of exploitation in the next 30 days.

Rockwell Automation Modbus TCP Server AOI prior to 2.04.00 is vulnerable to an unauthorized user sending a malformed message that could cause the controller to respond with a copy of the most recent response to the last valid request. If exploited, an unauthorized user could read the connected device’s Modbus TCP Server AOI information.

Affected products

  • Rockwellautomation Modbus TCP Server Add On Instructions: from 2.00.00, before 2.04.00 (fixed in 2.04.00)

Published 2023-03-17. Last modified 2026-06-17.