ZeroHour

CVE-2024-6207

CVSS 4.0
8.7 high
EPSS
<1%p44
Published
()
Modified
Description

CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and send a specially crafted CIP message to the device. If exploited, a threat actor could help prevent access to the legitimate user and end connections to connected devices including the workstation. To recover the controllers, a download is required which ends any process that the controller is running.

Vendors
rockwellautomation
Products
controllogix 5580 firmware, controllogix 5580 process firmware, guardlogix 5580 firmware, compactlogix 5380 firmware, compact guardlogix 5380 sil 2 firmware, compact guardlogix 5380 sil 3 firmware, compactlogix 5480 firmware, factorytalk logix echo firmware
Weakness
CWE-20
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.