Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-46834 | Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result in a major nonrecoverable fault(MNRF/Assert). This vulnerability could be exploited by sending abnormal packets to the mDNS port. If exploited, the availability of the device would be compromised. |
Solution
Affected Product First Known in firmware revision Corrected in firmware revision ControlLogix® 5580 V34.011 V34.014, V35.013, V36.011 and later GuardLogix 5580 V34.011 V34.014, V35.013, V36.011 and later 1756-EN4 V4.001 V6.001 and later CompactLogix 5380 V34.011 V34.014, V35.013, V36.011 and later Compact GuardLogix 5380 V34.011 V34.014, V35.013, V36.011 and later CompactLogix 5480 V34.011 V34.014, V35.013, V36.011 and later Mitigations and Workarounds Users using the affected software and who are not able to upgrade to one of the corrected versions are encouraged to apply the risk mitigations, where possible. · Users who do not use CIP Security with Rockwell Automation Products Application Technique https://literature.rockwellautomation.com/idc/groups/literature/documents/at/secure-at001_-en-p.pdf · Security Best Practices https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight
Workaround
No workaround given by the vendor.
No history.
Status: PUBLISHED
Assigner: Rockwell
Published:
Updated: 2024-08-01T21:18:06.865Z
Reserved: 2024-06-05T16:47:18.275Z
Link: CVE-2024-5659
Updated: 2024-08-01T21:18:06.865Z
Status : Awaiting Analysis
Published: 2024-06-14T17:15:51.600
Modified: 2024-11-21T09:48:06.543
Link: CVE-2024-5659
No data.
OpenCVE Enrichment
No data.
EUVD