A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, a disruption in the CIP communication will occur and a manual restart will be required by the user to recover it.
No analysis available yet.
Vendor Solution
There is no fix currently for this vulnerability. Users using the affected software are encouraged to apply risk mitigations and security best practices, where possible. * Implement network segmentation confirming the device is on an isolated network. * Disable the web server https://literature.rockwellautomation.com/idc/groups/literature/documents/um/520-um002_-en-e.pdf , if not needed. The web server is disabled by default. Disabling this feature is available in v2.001.x and later. * Security Best Practices https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-27377 | A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, a disruption in the CIP communication will occur and a manual restart will be required by the user to recover it. |
Fri, 31 Jan 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rockwellautomation
Rockwellautomation powerflex 527 Ac Drives Rockwellautomation powerflex 527 Ac Drives Firmware |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:h:rockwellautomation:powerflex_527_ac_drives:-:*:*:*:*:*:*:* cpe:2.3:o:rockwellautomation:powerflex_527_ac_drives_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Rockwellautomation
Rockwellautomation powerflex 527 Ac Drives Rockwellautomation powerflex 527 Ac Drives Firmware |
Status: PUBLISHED
Assigner: Rockwell
Published:
Updated: 2024-08-12T20:34:49.585Z
Reserved: 2024-03-13T14:45:10.183Z
Link: CVE-2024-2426
Updated: 2024-08-01T19:11:53.564Z
Status : Analyzed
Published: 2024-03-25T21:15:47.480
Modified: 2025-01-31T15:41:55.917
Link: CVE-2024-2426
No data.
OpenCVE Enrichment
No data.
EUVD