CVE Database
/

CVE-2024-3493

Back to search

CVE-2024-3493

Published: Apr 15, 2024

Modified: Aug 12, 2024

PUBLISHED

CVSS v3.1

8.6

HIGH

Description

A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause a major nonrecoverable fault (MNRF) Rockwell Automation's ControlLogix 5580, Guard Logix 5580, CompactLogix 5380, and 1756-EN4TR. If exploited, the affected product will become unavailable and require a manual restart to recover it. Additionally, an MNRF could result in a loss of view and/or control of connected devices.

VendorProductVersions

Rockwell Automation

ControlLogix 5580

affected
v35.011

Rockwell Automation

GuardLogix 5580

affected
v35.011

Rockwell Automation

CompactLogix 5380

affected
v5.001

Rockwell Automation

1756-EN4TR

affected
v5.001

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Changed

Confidentiality

None

Integrity

None

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now