PT-2017-16840 · Rockwell Automation · Compactlogix 5380+1
Published
2017-05-06
·
Updated
2022-03-23
·
CVE-2017-6024
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Rockwell Automation ControlLogix 5580 controllers versions V28.011 through V28.013
Rockwell Automation ControlLogix 5580 controllers version V29.011
Rockwell Automation CompactLogix 5380 controllers version V28.011
Rockwell Automation CompactLogix 5380 controllers version V29.011
Description
A Resource Exhaustion issue may allow an attacker to cause a denial of service condition by sending a series of specific CIP-based commands to the controller.
Recommendations
For Rockwell Automation ControlLogix 5580 controllers versions V28.011 through V28.013, update to a version that includes a fix for this issue.
For Rockwell Automation ControlLogix 5580 controllers version V29.011, update to a version that includes a fix for this issue.
For Rockwell Automation CompactLogix 5380 controllers version V28.011, update to a version that includes a fix for this issue.
For Rockwell Automation CompactLogix 5380 controllers version V29.011, update to a version that includes a fix for this issue.
As a temporary workaround, consider restricting access to the CIP-based commands to minimize the risk of exploitation.
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Compactlogix 5380
Controllogix 5580