Vulnerability Description
Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result in a major nonrecoverable fault(MNRF/Assert). This vulnerability could be exploited by sending abnormal packets to the mDNS port. If exploited, the availability of the device would be compromised.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rockwellautomation | Controllogix 5580 Firmware | 34.011 |
| Rockwellautomation | Controllogix 5580 | - |
| Rockwellautomation | Guardlogix 5580 Firmware | 34.011 |
| Rockwellautomation | Guardlogix 5580 | - |
| Rockwellautomation | 1756-En4 Firmware | 4.001 |
| Rockwellautomation | 1756-En4 | - |
| Rockwellautomation | Compactlogix 5380 Firmware | 34.011 |
| Rockwellautomation | Compactlogix 5380 | - |
| Rockwellautomation | Compact Guardlogix 5380 Firmware | 34.011 |
| Rockwellautomation | Compact Guardlogix 5380 | - |
| Rockwellautomation | Compactlogix 5480 Firmware | 34.011 |
| Rockwellautomation | Compactlogix 5480 | - |
Related Weaknesses (CWE)
References
- https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisoVendor Advisory
- https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisoVendor Advisory
FAQ
What is CVE-2024-5659?
CVE-2024-5659 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result in a major nonrecoverable fault(MNRF/Assert). This vulnerability could be explo...
How severe is CVE-2024-5659?
CVE-2024-5659 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-5659?
Check the references section above for vendor advisories and patch information. Affected products include: Rockwellautomation Controllogix 5580 Firmware, Rockwellautomation Controllogix 5580, Rockwellautomation Guardlogix 5580 Firmware, Rockwellautomation Guardlogix 5580, Rockwellautomation 1756-En4 Firmware.