CVE Database
/

CVE-2020-6998

Back to search

CVE-2020-6998

Published: Jul 27, 2022

Modified: Apr 17, 2025

PUBLISHED

CVSS v3.1

5.8

MEDIUM

Description

The connection establishment algorithm found in Rockwell Automation CompactLogix 5370 and ControlLogix 5570 versions 33 and prior does not sufficiently manage its control flow during execution, creating an infinite loop. This may allow an attacker to send specially crafted CIP packet requests to a controller, which may cause denial-of-service conditions in communications with other products.

VendorProductVersions

Rockwell Automation

Armor Compact GuardLogix 5370 controllers

affected
unspecified - <= versions 33 and prior

Rockwell Automation

Armor GuardLogix Safety Controllers

affected
unspecified - <= versions 33 and prior

Rockwell Automation

CompactLogix 5370 L1 controllers

affected
unspecified - <= versions 33 and prior

Rockwell Automation

CompactLogix 5370 L2 controllers

affected
unspecified - <= versions 33 and prior

Rockwell Automation

CompactLogix 5370 L3 controllers

affected
unspecified - <= versions 33 and prior

Rockwell Automation

Compact GuardLogix 5370 controllers

affected
unspecified - <= versions 33 and prior

Rockwell Automation

ControlLogix 5570 controllers

affected
unspecified - <= versions 33 and prior

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Changed

Confidentiality

None

Integrity

None

Availability

Low

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now