PT-2024-6556 · Rockwell Automation · Rockwell Automation Sequence Manager

Published

2024-07-16

·

Updated

2024-09-30

·

CVE-2024-6436

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Rockwell Automation Sequence Manager (affected versions not specified)
Description: The issue is related to an input validation problem that could allow a malicious user to send malformed packets to the server, resulting in a denial-of-service condition. If exploited, the device would become unresponsive and require a manual restart for recovery. Additionally, exploitation could lead to a loss of view for the downstream equipment sequences in the controller, preventing users from viewing the status or commanding the equipment sequences, although the equipment sequence would continue to execute uninterrupted.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-07700
CVE-2024-6436

Affected Products

Rockwell Automation Sequence Manager