A vulnerability exists in the Rockwell Automation controllers that allows a malformed CIP request to cause a major non-recoverable fault (MNRF) and a denial-of-service condition (DOS).
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:HRockwellautomation Compact Guardlogix 5370
HWRockwellautomationall versionsRockwellautomation Compact Guardlogix 5370 Firmware
OSRockwellautomation28 – 33Rockwellautomation Compact Guardlogix 5380
HWRockwellautomationall versionsRockwellautomation Compact Guardlogix 5380 Firmware
OSRockwellautomation28 – 33Rockwellautomation Compactlogix 5370
HWRockwellautomationall versionsRockwellautomation Compactlogix 5370 Firmware
OSRockwellautomation20 – 33Rockwellautomation Controllogix 5570
HWRockwellautomationall versionsRockwellautomation Controllogix 5570 Firmware
OSRockwellautomation20 – 33Rockwellautomation Controllogix 5570 Redundancy
HWRockwellautomationall versionsRockwellautomation Controllogix 5570 Redundancy Firmware
OSRockwellautomation20 – 33Rockwellautomation Guardlogix 5570
HWRockwellautomationall versionsRockwellautomation Guardlogix 5570 Firmware
OSRockwellautomation20 – 33
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2021-22681CRITICAL9.8⚠ KEVPL ✓same product
Rockwell Automation — pominięcie weryfikacji klucza uwierzytelnienia w sterownikach Logix
CVE-2022-1161CRITICAL10.0PL ✓same product
Rozbieżność kodu wykonywalnego i czytelnego w sterownikach Rockwell Automation Logix
CVE-2024-8626HIGH8.7same product
Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A...
CVE-2024-5659HIGH8.3same product
Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network...
CVE-2024-3493HIGH8.6same product
A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices tha...