Exploitable Vulnerability Could Prevent Access to Legitimate Users and End Connections to Connected Devices
CVE-2024-6207
7.5HIGH
Key Information:
- Vendor
Rockwell Automation
- Vendor
- CVE Published:
- 14 October 2024
What is CVE-2024-6207?
The vulnerability allows a threat actor to exploit a flaw in the processing of specially crafted CIP messages sent to Rockwell Automation Controllers. This can lead to unauthorized disruption of service, preventing legitimate users from gaining access and possibly severing connections to devices within the network, including workstations. Recovery from such an incident necessitates a download process, which forcibly halts any ongoing controller operations, impacting production and operational efficiency.
Affected Version(s)
Compact GuardLogix 5380 SIL 2 V31.011
Compact GuardLogix 5380 SIL 3 V32.013
CompactLogix 5380 V28.011