Vulnerability Description
An input validation vulnerability exists in the Rockwell Automation 5015-AENFTXT that causes the secondary adapter to result in a major nonrecoverable fault (MNRF) when malicious input is entered. If exploited, the availability of the device will be impacted, and a manual restart is required. Additionally, a malformed PTP packet is needed to exploit this vulnerability.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rockwellautomation | 5015-Aenftxt Firmware | 2.011 |
| Rockwellautomation | 5015-Aenftxt | - |
Related Weaknesses (CWE)
References
- https://www.rockwellautomation.com/en-us/support/advisory.SD1667.htmlBroken LinkVendor Advisory
- https://www.rockwellautomation.com/en-us/support/advisory.SD1667.htmlBroken LinkVendor Advisory
FAQ
What is CVE-2024-2424?
CVE-2024-2424 is a vulnerability with a CVSS score of 7.5 (HIGH). An input validation vulnerability exists in the Rockwell Automation 5015-AENFTXT that causes the secondary adapter to result in a major nonrecoverable fault (MNRF) when malicious input is entered. If...
How severe is CVE-2024-2424?
CVE-2024-2424 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-2424?
Check the references section above for vendor advisories and patch information. Affected products include: Rockwellautomation 5015-Aenftxt Firmware, Rockwellautomation 5015-Aenftxt.