CVE-2024-6207
Published: Oct 14, 2024
Modified: Oct 15, 2024
CVSS v3.1
7.5
Description
CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and send a specially crafted CIP message to the device. If exploited, a threat actor could help prevent access to the legitimate user and end connections to connected devices including the workstation. To recover the controllers, a download is required which ends any process that the controller is running.
| Vendor | Product | Versions |
|---|---|---|
Rockwell Automation | ControlLogix® 5580 | affected V28.011 |
Rockwell Automation | ControlLogix® 5580 Process | affected V33.011 |
Rockwell Automation | GuardLogix 5580 | affected V31.011 |
Rockwell Automation | CompactLogix 5380 | affected V28.011 |
Rockwell Automation | Compact GuardLogix 5380 SIL 2 | affected V31.011 |
Rockwell Automation | Compact GuardLogix 5380 SIL 3 | affected V32.013 |
Rockwell Automation | CompactLogix 5480 | affected V32.011 |
Rockwell Automation | FactoryTalk® Logix Echo | affected V33.011 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now