PT-2024-8137 · Rockwell Automation · Powerflex 600T

Published

2024-10-07

·

Updated

2025-09-22

·

CVE-2024-9124

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Rockwell Automation PowerFlex 600T (affected versions not specified)
Description: The issue is related to insufficient exception handling in the PowerFlex 6000T variable frequency drive's firmware, which can be exploited by a remote attacker to cause a denial-of-service. This can happen when the device is overloaded with requests, making it unavailable. In some cases, the device may require a power cycle to recover if it does not re-establish a connection after it stops receiving requests.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Improper Check for Exceptional Conditions

Weakness Enumeration

Related Identifiers

BDU:2024-09678
CVE-2024-9124

Affected Products

Powerflex 600T