ZeroHour

CVE-2024-5659

CVSS 4.0
8.3 high
EPSS
<1%p24
Published
()
Modified
Description

Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result in a major nonrecoverable fault(MNRF/Assert). This vulnerability could be exploited by sending abnormal packets to the mDNS port. If exploited, the availability of the device would be compromised.

Vendors
rockwellautomation
Products
controllogix 5580 firmware, guardlogix 5580 firmware, 1756-en4 firmware, compactlogix 5380 firmware, compact guardlogix 5380 firmware, compactlogix 5480 firmware
Weakness
CWE-670
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.