Impact
A buffer overflow in the boot firmware of Rockwell Automation controllers 5380, 5480, and 5580 allows a malicious user to write invalid data, causing the device to enter a major non-recoverable fault. This leads to a denial of service, rendering the controller unusable until physically reset or repaired. The weakness is identified as CWE-120 and affects the availability of the device.
Affected Systems
The affected hardware includes Rockwell Automation CompactLogix 5380 Recovery Image, Compact GuardLogix 5380 Recovery Image, Compact Logix 5480 Recovery Image, Control Logix 5580 Recovery Image, and Guard Logix 5580 Recovery Image. Firmware versions earlier than 1.072 are vulnerable; controllers running 1.072 or newer are not affected. No other version or product information is supplied.
Risk and Exploitability
The CVSS score of 9.2 denotes high severity, while the EPSS score of less than 1% indicates a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack would require an adversary capable of providing corrupted firmware or file data to the controller, which typically implies local or privileged access to the update interface. No public exploit is known, so the risk is mainly due to potential internal threat actors or attackers who gain physical or privileged network access.
OpenCVE Enrichment