Description

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper traffic throttling in the device. If multiple data packets are sent to the device repeatedly the device will crash and require a manual restart to recover.

Published: 2024-03-25
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

There is no fix currently for this vulnerability. Users using the affected software are encouraged to apply risk mitigations and security best practices, where possible. * Implement network segmentation confirming the device is on an isolated network. * Disable the web server https://literature.rockwellautomation.com/idc/groups/literature/documents/um/520-um002_-en-e.pdf , if not needed. The web server is disabled by default. Disabling this feature is available in v2.001.x and later. * Security Best Practices https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-27378 A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper traffic throttling in the device. If multiple data packets are sent to the device repeatedly the device will crash and require a manual restart to recover.
History

Fri, 31 Jan 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Rockwellautomation
Rockwellautomation powerflex 527 Ac Drives
Rockwellautomation powerflex 527 Ac Drives Firmware
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:h:rockwellautomation:powerflex_527_ac_drives:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:powerflex_527_ac_drives_firmware:*:*:*:*:*:*:*:*
Vendors & Products Rockwellautomation
Rockwellautomation powerflex 527 Ac Drives
Rockwellautomation powerflex 527 Ac Drives Firmware

Subscriptions

Rockwellautomation Powerflex 527 Ac Drives Powerflex 527 Ac Drives Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2024-08-21T14:57:19.700Z

Reserved: 2024-03-13T14:46:09.865Z

Link: CVE-2024-2427

cve-icon Vulnrichment

Updated: 2024-08-01T19:11:53.547Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-25T21:15:47.660

Modified: 2025-01-31T15:41:57.463

Link: CVE-2024-2427

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses