Impact
The vulnerability is caused by improper handling of exceptional conditions when the FLEX 5000 EtherNet/IP Adapter processes crafted CIP packets, causing the module to crash and requiring a power cycle to recover. The crash results in a denial of service that interrupts all I/O functions provided by the adapter, representing a significant availability loss.
Affected Systems
Rockwell Automation’s FLEX 5000 EtherNet/IP Adapter is affected. Versions earlier than 6.012 contain the flaw. All installations of this equipment that have not yet upgraded to firmware 6.012 or later remain vulnerable.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity. The EPSS score of less than one percent shows a very low current exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that attackers could send specially crafted CIP packets over the network to trigger the failure, so the attack vector is likely remote network access without special privileges.
OpenCVE Enrichment