Denial-of-Service Vulnerability in Rockwell Automation Products
CVE-2025-24478

7.1HIGH

What is CVE-2025-24478?

A denial-of-service vulnerability has been identified within Rockwell Automation products that allows remote, non-privileged users to exploit the system. By sending specially crafted requests, an attacker could trigger a nonrecoverable fault, rendering the affected system inoperable. This vulnerability poses significant risks to operational continuity, emphasizing the need for immediate remediation to safeguard against potential exploitation.

Affected Version(s)

Compact GuardLogix 5380 SIL 3 33.011

Compact GuardLogix 5380 SIL 3 33.012

Compact GuardLogix 5380 SIL 3 33.015

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.