A denial-of-service vulnerability exists via the CIP/Modbus port in the Rockwell Automation Micro850/870 (2080 -L50E/2080 -L70E). If exploited, the CIP/Modbus communication may be disrupted for short duration.

Subscriptions

Vendors Products
Rockwellautomation Subscribe
Micro850 Firmware Subscribe
Micro870 Firmware Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-48466 A denial-of-service vulnerability exists via the CIP/Modbus port in the Rockwell Automation Micro850/870 (2080 -L50E/2080 -L70E). If exploited, the CIP/Modbus communication may be disrupted for short duration.
Fixes

Solution

* Update to the corrected version:  v22.011 or later.  Customers using the affected software are encouraged to apply security best practices, if possible. ·       For information on how to mitigate Security Risks on industrial automation control systems, we encourage customers to implement our suggested security best practices https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight  to minimize the risk of the vulnerability


Workaround

No workaround given by the vendor.

History

Tue, 13 Aug 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Rockwellautomation
Rockwellautomation micro850 Firmware
Rockwellautomation micro870 Firmware
CPEs cpe:2.3:o:rockwellautomation:micro850_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:micro870_firmware:-:*:*:*:*:*:*:*
Vendors & Products Rockwellautomation
Rockwellautomation micro850 Firmware
Rockwellautomation micro870 Firmware
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 13 Aug 2024 18:00:00 +0000

Type Values Removed Values Added
Description A denial-of-service vulnerability exists via the CIP/Modbus port in the Rockwell Automation Micro850/870 (2080 -L50E/2080 -L70E). If exploited, the CIP/Modbus communication may be disrupted for short duration.
Title Rockwell Automation Micro850/870 Vulnerable to denial-of-service Vulnerability via CIP/Modbus Port
Weaknesses CWE-400
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2024-08-13T18:37:13.727Z

Reserved: 2024-08-06T17:59:43.596Z

Link: CVE-2024-7567

cve-icon Vulnrichment

Updated: 2024-08-13T18:37:09.473Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-13T18:15:32.680

Modified: 2024-08-14T02:07:05.410

Link: CVE-2024-7567

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses