HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2024-3493

CVSS 8.6v3.1pub. 2024-04-15upd. 2025-03-04

A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause a major nonrecoverable fault (MNRF) Rockwell Automation's ControlLogix 5580, Guard Logix 5580, CompactLogix 5380, and 1756-EN4TR. If exploited, the affected product will become unavailable and require a manual restart to recover it. Additionally, an MNRF could result in a loss of view and/or control of connected devices.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
  • Rockwellautomation 1756 En4tr

    HW
    Rockwellautomation
    all versions
  • Rockwellautomation 1756 En4tr Firmware

    OS
    Rockwellautomation
    5.001
  • Rockwellautomation Compact Guardlogix 5380

    HW
    Rockwellautomation
    all versions
  • Rockwellautomation Compact Guardlogix 5380 Firmware

    OS
    Rockwellautomation
    35.011
  • Rockwellautomation Compactlogix 5380

    HW
    Rockwellautomation
    all versions
  • Rockwellautomation Compactlogix 5380 Firmware

    OS
    Rockwellautomation
    35.011
  • Rockwellautomation Compactlogix 5380 Process

    HW
    Rockwellautomation
    all versions
  • Rockwellautomation Compactlogix 5380 Process Firmware

    OS
    Rockwellautomation
    35.011
  • Rockwellautomation Compactlogix 5480

    HW
    Rockwellautomation
    all versions
  • Rockwellautomation Compactlogix 5480 Firmware

    OS
    Rockwellautomation
    35.011
  • Rockwellautomation Controllogix 5580

    HW
    Rockwellautomation
    all versions
  • Rockwellautomation Controllogix 5580 Firmware

    OS
    Rockwellautomation
    35.011
  • Rockwellautomation Controllogix 5580 Process

    HW
    Rockwellautomation
    all versions
  • Rockwellautomation Controllogix 5580 Process Firmware

    OS
    Rockwellautomation
    35.011
  • Rockwellautomation Guardlogix 5580

    HW
    Rockwellautomation
    all versions
  • Rockwellautomation Guardlogix 5580 Firmware

    OS
    Rockwellautomation
    35.011
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2021-22681CRITICAL9.8⚠ KEVPL ✓same product

Rockwell Automation — pominięcie weryfikacji klucza uwierzytelnienia w sterownikach Logix

CVE-2022-1161CRITICAL10.0PL ✓same product

Rozbieżność kodu wykonywalnego i czytelnego w sterownikach Rockwell Automation Logix

CVE-2025-8007HIGH7.1same product

A security issue exists in the protected mode of 1756-EN4TR and 1756-EN2TR communication modules, where a Conc...

CVE-2025-8008HIGH7.1same product

A security issue exists in the protected mode of EN4TR devices, where sending specifically crafted messages du...

CVE-2025-9166HIGH8.2same product

A denial-of-service security issue exists in the affected product and version. The security issue stems from t...