Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multiple actions on certain web pages of the product causing the affected products to become fully unavailable and require a power cycle to recover.
History

Tue, 08 Oct 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Rockwellautomation
Rockwellautomation 1756-en4tr Firmware
Rockwellautomation compact Guardlogix 5380 Firmware
Rockwellautomation compactlogix 5380 Firmware
Rockwellautomation compactlogix 5480 Firmware
Rockwellautomation guardlogix 5580 Firmware
CPEs cpe:2.3:o:rockwellautomation:1756-en4tr_firmware:3.002:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:compact_guardlogix_5380_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:compactlogix_5380_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:compactlogix_5480_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:guardlogix_5580_firmware:*:*:*:*:*:*:*:*
Vendors & Products Rockwellautomation
Rockwellautomation 1756-en4tr Firmware
Rockwellautomation compact Guardlogix 5380 Firmware
Rockwellautomation compactlogix 5380 Firmware
Rockwellautomation compactlogix 5480 Firmware
Rockwellautomation guardlogix 5580 Firmware
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Oct 2024 16:45:00 +0000

Type Values Removed Values Added
Description Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multiple actions on certain web pages of the product causing the affected products to become fully unavailable and require a power cycle to recover.
Title Logix Controllers Vulnerable to Denial-of-Service Vulnerability
Weaknesses CWE-400
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published: 2024-10-08T16:35:04.513Z

Updated: 2024-10-08T17:36:25.719Z

Reserved: 2024-09-09T20:33:30.575Z

Link: CVE-2024-8626

cve-icon Vulnrichment

Updated: 2024-10-08T17:35:58.753Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-08T17:15:56.240

Modified: 2024-10-10T12:56:30.817

Link: CVE-2024-8626

cve-icon Redhat

No data.