PT-2017-16840 · Rockwell Automation · Compactlogix 5380+1
Publicado
2017-05-06
·
Atualizado
2022-03-23
·
CVE-2017-6024
CVSS v2.0
7.1
Alta
| Vetor | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Rockwell Automation ControlLogix 5580 controllers versions V28.011 through V28.013
Rockwell Automation ControlLogix 5580 controllers version V29.011
Rockwell Automation CompactLogix 5380 controllers version V28.011
Rockwell Automation CompactLogix 5380 controllers version V29.011
Description
A Resource Exhaustion issue may allow an attacker to cause a denial of service condition by sending a series of specific CIP-based commands to the controller.
Recommendations
For Rockwell Automation ControlLogix 5580 controllers versions V28.011 through V28.013, update to a version that includes a fix for this issue.
For Rockwell Automation ControlLogix 5580 controllers version V29.011, update to a version that includes a fix for this issue.
For Rockwell Automation CompactLogix 5380 controllers version V28.011, update to a version that includes a fix for this issue.
For Rockwell Automation CompactLogix 5380 controllers version V29.011, update to a version that includes a fix for this issue.
As a temporary workaround, consider restricting access to the CIP-based commands to minimize the risk of exploitation.
Correção
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Compactlogix 5380
Controllogix 5580