The connection establishment algorithm found in Rockwell Automation CompactLogix 5370 and ControlLogix 5570 versions 33 and prior does not sufficiently manage its control flow during execution, creating an infinite loop. This may allow an attacker to send specially crafted CIP packet requests to a controller, which may cause denial-of-service conditions in communications with other products.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2022-07-27T20:18:00
Updated: 2024-08-04T09:18:02.993Z
Reserved: 2020-01-14T00:00:00
Link: CVE-2020-6998
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-07-27T21:15:08.297
Modified: 2024-11-21T05:36:27.750
Link: CVE-2020-6998
Redhat
No data.