Impact
The vulnerability is a buffer overflow in the file handling code of the CompactLogix, Compact GuardLogix, ControlLogix, and GuardLogix controllers, specifically the 5370 and 5570 series. When a malicious user writes invalid file data to the controller, the internal buffer overflows, causing the device to enter a major non-recoverable fault (MNRF). This flaw is an instance of CWE-120 and results in a denial‑of‑service that stops the controller from continuing operation.
Affected Systems
Affected systems are the Rockwell Automation CompactLogix, Compact GuardLogix, ControlLogix, and GuardLogix controllers – specifically the 5370 and 5570 series. No specific firmware revision numbers are listed, so any controller running the relevant firmware that includes the vulnerable file‑handling code may be impacted.
Risk and Exploitability
The CVSS score of 9.2 indicates a high‑severity vulnerability, and the EPSS score of less than 1% suggests that exploitation is currently unlikely but not impossible. The device is not listed in the CISA KEV catalog. The flaw can be exploited by an adversary who has the ability to upload or overwrite file data on the controller, potentially via a network session or physical access. Based on the description, it is inferred that the attack vector is likely remote but could also occur locally if file transfer overflow leads to a fatal fault that requires a power cycle and often a firmware reinstall, effectively denying service.
OpenCVE Enrichment