PT-2024-6556 · Rockwell Automation · Rockwell Automation Sequence Manager
Published
2024-07-16
·
Updated
2024-09-30
·
CVE-2024-6436
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
Rockwell Automation Sequence Manager (affected versions not specified)
Description:
The issue is related to an input validation problem that could allow a malicious user to send malformed packets to the server, resulting in a denial-of-service condition. If exploited, the device would become unresponsive and require a manual restart for recovery. Additionally, exploitation could lead to a loss of view for the downstream equipment sequences in the controller, preventing users from viewing the status or commanding the equipment sequences, although the equipment sequence would continue to execute uninterrupted.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rockwell Automation Sequence Manager