A denial-of-service vulnerability exists via the CIP/Modbus port in the Rockwell Automation Micro850/870 (2080 -L50E/2080 -L70E). If exploited, the CIP/Modbus communication may be disrupted for short duration.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-48466 A denial-of-service vulnerability exists via the CIP/Modbus port in the Rockwell Automation Micro850/870 (2080 -L50E/2080 -L70E). If exploited, the CIP/Modbus communication may be disrupted for short duration.
Fixes

Solution

* Update to the corrected version:  v22.011 or later.  Customers using the affected software are encouraged to apply security best practices, if possible. ·       For information on how to mitigate Security Risks on industrial automation control systems, we encourage customers to implement our suggested security best practices https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight  to minimize the risk of the vulnerability


Workaround

No workaround given by the vendor.

History

Tue, 13 Aug 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Rockwellautomation
Rockwellautomation micro850 Firmware
Rockwellautomation micro870 Firmware
CPEs cpe:2.3:o:rockwellautomation:micro850_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:micro870_firmware:-:*:*:*:*:*:*:*
Vendors & Products Rockwellautomation
Rockwellautomation micro850 Firmware
Rockwellautomation micro870 Firmware
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 13 Aug 2024 18:00:00 +0000

Type Values Removed Values Added
Description A denial-of-service vulnerability exists via the CIP/Modbus port in the Rockwell Automation Micro850/870 (2080 -L50E/2080 -L70E). If exploited, the CIP/Modbus communication may be disrupted for short duration.
Title Rockwell Automation Micro850/870 Vulnerable to denial-of-service Vulnerability via CIP/Modbus Port
Weaknesses CWE-400
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2024-08-13T18:37:13.727Z

Reserved: 2024-08-06T17:59:43.596Z

Link: CVE-2024-7567

cve-icon Vulnrichment

Updated: 2024-08-13T18:37:09.473Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-13T18:15:32.680

Modified: 2024-08-14T02:07:05.410

Link: CVE-2024-7567

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.