Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multiple actions on certain web pages of the product causing the affected products to become fully unavailable and require a power cycle to recover.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-49305 Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multiple actions on certain web pages of the product causing the affected products to become fully unavailable and require a power cycle to recover.
Fixes

Solution

Affected Product      First Known in firmware Revision         Corrected in Firmware Revision         CompactLogix 5380 controllers         v33.011 <                     * v33.015 and later for versions 33     * v34.011 and later               Compact GuardLogix® 5380 controllers         v33.011<         CompactLogix 5480 controllers         v33.011<         ControlLogix 5580 controllers         v33.011<         GuardLogix 5580 controllers         v33.011<         1756-EN4TR         v3.002         * 4.001 and later     Mitigations and Workarounds Customers using the affected versions are encouraged to upgrade to corrected firmware versions. We also strongly encourage customers to implement our suggested security best practices to minimize the risk of the vulnerability. * Security Best Practices https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight


Workaround

No workaround given by the vendor.

History

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00085}

epss

{'score': 0.00112}


Tue, 08 Oct 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Rockwellautomation
Rockwellautomation 1756-en4tr Firmware
Rockwellautomation compact Guardlogix 5380 Firmware
Rockwellautomation compactlogix 5380 Firmware
Rockwellautomation compactlogix 5480 Firmware
Rockwellautomation guardlogix 5580 Firmware
CPEs cpe:2.3:o:rockwellautomation:1756-en4tr_firmware:3.002:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:compact_guardlogix_5380_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:compactlogix_5380_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:compactlogix_5480_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:guardlogix_5580_firmware:*:*:*:*:*:*:*:*
Vendors & Products Rockwellautomation
Rockwellautomation 1756-en4tr Firmware
Rockwellautomation compact Guardlogix 5380 Firmware
Rockwellautomation compactlogix 5380 Firmware
Rockwellautomation compactlogix 5480 Firmware
Rockwellautomation guardlogix 5580 Firmware
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Oct 2024 16:45:00 +0000

Type Values Removed Values Added
Description Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multiple actions on certain web pages of the product causing the affected products to become fully unavailable and require a power cycle to recover.
Title Logix Controllers Vulnerable to Denial-of-Service Vulnerability
Weaknesses CWE-400
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2024-10-08T17:36:25.719Z

Reserved: 2024-09-09T20:33:30.575Z

Link: CVE-2024-8626

cve-icon Vulnrichment

Updated: 2024-10-08T17:35:58.753Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2024-10-08T17:15:56.240

Modified: 2024-10-10T12:56:30.817

Link: CVE-2024-8626

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.