PT-2017-16840 · Rockwell Automation · Compactlogix 5380+1

Published

2017-05-06

·

Updated

2022-03-23

·

CVE-2017-6024

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Rockwell Automation ControlLogix 5580 controllers versions V28.011 through V28.013 Rockwell Automation ControlLogix 5580 controllers version V29.011 Rockwell Automation CompactLogix 5380 controllers version V28.011 Rockwell Automation CompactLogix 5380 controllers version V29.011
Description A Resource Exhaustion issue may allow an attacker to cause a denial of service condition by sending a series of specific CIP-based commands to the controller.
Recommendations For Rockwell Automation ControlLogix 5580 controllers versions V28.011 through V28.013, update to a version that includes a fix for this issue. For Rockwell Automation ControlLogix 5580 controllers version V29.011, update to a version that includes a fix for this issue. For Rockwell Automation CompactLogix 5380 controllers version V28.011, update to a version that includes a fix for this issue. For Rockwell Automation CompactLogix 5380 controllers version V29.011, update to a version that includes a fix for this issue. As a temporary workaround, consider restricting access to the CIP-based commands to minimize the risk of exploitation.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-6024

Affected Products

Compactlogix 5380
Controllogix 5580