CVE Vulnerabilities

CVE-2024-6207

Published: Oct 14, 2024 | Modified: Oct 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html  and send a specially crafted CIP message to the device. If exploited, a threat actor could help prevent access to the legitimate user and end connections to connected devices including the workstation. To recover the controllers, a download is required which ends any process that the controller is running.

Affected Software

Name Vendor Start Version End Version
Controllogix_5580_firmware Rockwellautomation 28.011 (including) 33.017 (excluding)
Controllogix_5580_firmware Rockwellautomation 34.011 (including) 34.014 (excluding)
Controllogix_5580_firmware Rockwellautomation 35.011 (including) 35.013 (excluding)

References