Impact
A buffer overflow flaw permits a remote user to load a malformed project file into a CompactLogix 5370, Compact GuardLogix 5370, ControlLogix 5570, or GuardLogix 5570 controller, causing the device to enter a major non‑recoverable fault and terminating all operations. The resulting denial of service requires a manual reset or firmware re‑installation. The weakness is the classic CWE‑120 buffer overflow.
Affected Systems
Rockwell Automation CompactLogix 5370, Compact GuardLogix 5370, ControlLogix 5570, and GuardLogix 5570 controllers are affected.
Risk and Exploitability
The CVSS score of 9.2 indicates critical severity. The EPSS score of <1% suggests a low probability of public exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote client sending a crafted project file over the controller’s network interface.
OpenCVE Enrichment