Description
CVE-2024-45825 IMPACT
A denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a malformed CIP packet is sent over the network to the device and results in a major nonrecoverable fault causing a denial-of-service.
Published: 2024-09-12
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Upgrade to V2.011


Vendor Workaround

Block communication to CIP classes 883 and 67 if it is not required

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-41619 CVE-2024-45825 IMPACT A denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a malformed CIP packet is sent over the network to the device and results in a major nonrecoverable fault causing a denial-of-service.
History

Wed, 02 Oct 2024 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Rockwellautomation 5015-u8ihft
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:h:rockwellautomation:5015-u8ihft:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:5015-u8ihft_firmware:1.011:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:5015-u8ihft_firmware:1.012:*:*:*:*:*:*:*
Vendors & Products Rockwellautomation 5015-u8ihft

Thu, 12 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Rockwellautomation
Rockwellautomation 5015-u8ihft Firmware
CPEs cpe:2.3:o:rockwellautomation:5015-u8ihft_firmware:*:*:*:*:*:*:*:*
Vendors & Products Rockwellautomation
Rockwellautomation 5015-u8ihft Firmware
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Sep 2024 14:45:00 +0000

Type Values Removed Values Added
Description CVE-2024-45825 IMPACT A denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a malformed CIP packet is sent over the network to the device and results in a major nonrecoverable fault causing a denial-of-service.
Title 5015-U8IHFT Denial-of-Service Vulnerability via CIP Message
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Rockwellautomation 5015-u8ihft 5015-u8ihft Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2024-09-12T15:03:21.086Z

Reserved: 2024-09-09T19:33:02.444Z

Link: CVE-2024-45825

cve-icon Vulnrichment

Updated: 2024-09-12T15:03:13.589Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-12T15:18:23.387

Modified: 2024-10-02T14:43:08.720

Link: CVE-2024-45825

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses