MEDIUM🇵🇱 Wersja polska

CVE-2020-6998

CVSS 5.8v3.1pub. 2022-07-27upd. 2025-04-17

The connection establishment algorithm found in Rockwell Automation CompactLogix 5370 and ControlLogix 5570 versions 33 and prior does not sufficiently manage its control flow during execution, creating an infinite loop. This may allow an attacker to send specially crafted CIP packet requests to a controller, which may cause denial-of-service conditions in communications with other products.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
  • Rockwellautomation Armor Compact Guardlogix 5370

    HW
    Rockwellautomation
    all versions
  • Rockwellautomation Armor Compact Guardlogix 5370 Firmware

    OS
    Rockwellautomation
    ≤ 33
  • Rockwellautomation Compact Guardlogix 5370

    HW
    Rockwellautomation
    all versions
  • Rockwellautomation Compact Guardlogix 5370 Firmware

    OS
    Rockwellautomation
    ≤ 33
  • Rockwellautomation Compactlogix 5370 L1

    HW
    Rockwellautomation
    all versions
  • Rockwellautomation Compactlogix 5370 L1 Firmware

    OS
    Rockwellautomation
    ≤ 33
  • Rockwellautomation Compactlogix 5370 L2

    HW
    Rockwellautomation
    all versions
  • Rockwellautomation Compactlogix 5370 L2 Firmware

    OS
    Rockwellautomation
    ≤ 33
  • Rockwellautomation Compactlogix 5370 L3

    HW
    Rockwellautomation
    all versions
  • Rockwellautomation Compactlogix 5370 L3 Firmware

    OS
    Rockwellautomation
    ≤ 33
  • Rockwellautomation Controllogix 5570

    HW
    Rockwellautomation
    all versions
  • Rockwellautomation Controllogix 5570 Firmware

    OS
    Rockwellautomation
    ≤ 33
  • Rockwellautomation Guardlogix 5560

    HW
    Rockwellautomation
    all versions
  • Rockwellautomation Guardlogix 5560 Firmware

    OS
    Rockwellautomation
    ≤ 33
  • Rockwellautomation Guardlogix 5570

    HW
    Rockwellautomation
    all versions
  • Rockwellautomation Guardlogix 5570 Firmware

    OS
    Rockwellautomation
    ≤ 33
  • Rockwellautomation Guardlogix 5580

    HW
    Rockwellautomation
    all versions
  • Rockwellautomation Guardlogix 5580 Firmware

    OS
    Rockwellautomation
    ≤ 33
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2021-22681CRITICAL9.8⚠ KEVPL ✓same product

Rockwell Automation — pominięcie weryfikacji klucza uwierzytelnienia w sterownikach Logix

CVE-2022-1161CRITICAL10.0PL ✓same product

Rozbieżność kodu wykonywalnego i czytelnego w sterownikach Rockwell Automation Logix

CVE-2019-10952CRITICAL9.8PL ✓same product

RCE i DoS w kontrolerach Rockwell Automation CompactLogix 5370 via HTTP/HTTPS

CVE-2024-6207HIGH8.7same product

CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html ...

CVE-2024-8626HIGH8.7same product

Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A...