A vulnerability exists in the Rockwell Automation controllers that allows a malformed CIP request to cause a major non-recoverable fault (MNRF) and a denial-of-service condition (DOS).
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:HRockwellautomation Compact Guardlogix 5370
HWRockwellautomationwszystkie wersjeRockwellautomation Compact Guardlogix 5370 Firmware
OSRockwellautomation28 – 33Rockwellautomation Compact Guardlogix 5380
HWRockwellautomationwszystkie wersjeRockwellautomation Compact Guardlogix 5380 Firmware
OSRockwellautomation28 – 33Rockwellautomation Compactlogix 5370
HWRockwellautomationwszystkie wersjeRockwellautomation Compactlogix 5370 Firmware
OSRockwellautomation20 – 33Rockwellautomation Controllogix 5570
HWRockwellautomationwszystkie wersjeRockwellautomation Controllogix 5570 Firmware
OSRockwellautomation20 – 33Rockwellautomation Controllogix 5570 Redundancy
HWRockwellautomationwszystkie wersjeRockwellautomation Controllogix 5570 Redundancy Firmware
OSRockwellautomation20 – 33Rockwellautomation Guardlogix 5570
HWRockwellautomationwszystkie wersjeRockwellautomation Guardlogix 5570 Firmware
OSRockwellautomation20 – 33
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Powiązane podatności
CVE-2021-22681CRITICAL9.8⚠ KEVPL ✓ten sam produkt
Rockwell Automation — pominięcie weryfikacji klucza uwierzytelnienia w sterownikach Logix
CVE-2022-1161CRITICAL10.0PL ✓ten sam produkt
Rozbieżność kodu wykonywalnego i czytelnego w sterownikach Rockwell Automation Logix
CVE-2024-8626HIGH8.7ten sam produkt
Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A...
CVE-2024-5659HIGH8.3ten sam produkt
Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network...
CVE-2024-3493HIGH8.6ten sam produkt
A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices tha...