Impact
The vulnerability is a denial‑of‑service issue in Rockwell Automation’s FLEX 5000 EtherNet/IP Adapter stemming from improper handling of exceptional conditions when the device processes specially crafted CIP packets. The fault can crash the adapter and requires a power cycle to recover. The crash results in a loss of availability for all I/O functions provided by the adapter.
Affected Systems
Rockwell Automation’s FLEX 5000 EtherNet/IP Adapter is affected. Firmware versions earlier than 6.012 contain the flaw. All installations that have not yet upgraded remain vulnerable.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. An EPSS score of less than one percent shows a very low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that attackers could send specially crafted CIP packets over the network to trigger the failure, so the attack vector is likely remote network access without special privileges.
OpenCVE Enrichment