PT-2021-2365 · Rockwell Automation · Compactlogix 5370+7
Published
2021-03-02
·
Updated
2022-08-04
·
CVE-2020-6998
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Rockwell Automation CompactLogix 5370 versions prior to 34
Rockwell Automation ControlLogix 5570 versions prior to 34
Rockwell Automation CompactLogix 5370 L1 versions prior to 34
Rockwell Automation CompactLogix 5370 L2 versions prior to 34
Rockwell Automation CompactLogix 5370 L3 versions prior to 34
Rockwell Automation Compact GuardLogix 5370 versions prior to 34
Rockwell Automation GuardLogix 5370 versions prior to 34
Rockwell Automation Compact GuardLogix versions prior to 34
Description
The connection establishment algorithm in the affected products does not manage its control flow during execution, creating an infinite loop. This may allow an attacker to send specially crafted CIP packet requests to a controller, which may cause denial-of-service conditions in communications with other products. An attacker can exploit this issue by sending a specially crafted CIP packet, potentially leading to a denial-of-service condition.
Recommendations
For Rockwell Automation CompactLogix 5370 versions prior to 34, update to version 34 or later.
For Rockwell Automation ControlLogix 5570 versions prior to 34, update to version 34 or later.
For Rockwell Automation CompactLogix 5370 L1 versions prior to 34, update to version 34 or later.
For Rockwell Automation CompactLogix 5370 L2 versions prior to 34, update to version 34 or later.
For Rockwell Automation CompactLogix 5370 L3 versions prior to 34, update to version 34 or later.
For Rockwell Automation Compact GuardLogix 5370 versions prior to 34, update to version 34 or later.
For Rockwell Automation GuardLogix 5370 versions prior to 34, update to version 34 or later.
For Rockwell Automation Compact GuardLogix versions prior to 34, update to version 34 or later.
Fix
Infinite Loop
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Compact Guardlogix
Compact Guardlogix 5370
Compactlogix 5370
Compactlogix 5370 L1
Compactlogix 5370 L2
Compactlogix 5370 L3
Controllogix 5570
Guardlogix 5370