Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-50812 | A denial-of-service and possible remote code execution vulnerability exists in the Rockwell Automation Power Monitor 1000. The vulnerability results in corruption of the heap memory which may compromise the integrity of the system, potentially allowing for remote code execution or a denial-of-service attack. |
Solution
Affected Products Affected firmware revision Corrected in firmware revision PM1k 1408-BC3A-485 <4.020 4.020 PM1k 1408-BC3A-ENT <4.020 4.020 PM1k 1408-TS3A-485 <4.020 4.020 PM1k 1408-TS3A-ENT <4.020 4.020 PM1k 1408-EM3A-485 <4.020 4.020 PM1k 1408-EM3A-ENT <4.020 4.020 PM1k 1408-TR1A-485 <4.020 4.020 PM1k 1408-TR2A-485 <4.020 4.020 PM1k 1408-EM1A-485 <4.020 4.020 PM1k 1408-EM2A-485 <4.020 4.020 PM1k 1408-TR1A-ENT <4.020 4.020 PM1k 1408-TR2A-ENT <4.020 4.020 PM1k 1408-EM1A-ENT <4.020 4.020 PM1k 1408-EM2A-ENT <4.020 4.020 Mitigations and Workarounds Users using the affected software, who are not able to upgrade to one of the corrected versions, are encouraged to apply security best practices, where possible. · Security Best Practices https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight
Workaround
No workaround given by the vendor.
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 18 Dec 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| Metrics |
ssvc
|
Wed, 18 Dec 2024 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A denial-of-service and possible remote code execution vulnerability exists in the Rockwell Automation Power Monitor 1000. The vulnerability results in corruption of the heap memory which may compromise the integrity of the system, potentially allowing for remote code execution or a denial-of-service attack. | |
| Title | Rockwell Automation PowerMonitor™ 1000 Denial of Service | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Rockwell
Published:
Updated: 2024-12-18T19:58:03.337Z
Reserved: 2024-12-09T17:50:51.305Z
Link: CVE-2024-12372
Updated: 2024-12-18T19:57:58.869Z
Status : Received
Published: 2024-12-18T16:15:11.050
Modified: 2024-12-18T20:15:22.167
Link: CVE-2024-12372
No data.
OpenCVE Enrichment
No data.
EUVD