Vulnerability Description
CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and send a specially crafted CIP message to the device. If exploited, a threat actor could help prevent access to the legitimate user and end connections to connected devices including the workstation. To recover the controllers, a download is required which ends any process that the controller is running.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rockwellautomation | Controllogix 5580 Firmware | >= 28.011, < 33.017 |
| Rockwellautomation | Controllogix 5580 | - |
| Rockwellautomation | Controllogix 5580 Process Firmware | >= 33.011, < 33.017 |
| Rockwellautomation | Controllogix 5580 Process | - |
| Rockwellautomation | Guardlogix 5580 Firmware | >= 31.011, < 33.017 |
| Rockwellautomation | Guardlogix 5580 | - |
| Rockwellautomation | Compactlogix 5380 Firmware | >= 28.011, < 33.017 |
| Rockwellautomation | Compactlogix 5380 | - |
| Rockwellautomation | Compact Guardlogix 5380 Sil 2 Firmware | >= 31.011, < 33.017 |
| Rockwellautomation | Compact Guardlogix 5380 Sil 2 | - |
| Rockwellautomation | Compact Guardlogix 5380 Sil 3 Firmware | >= 32.013, < 33.017 |
| Rockwellautomation | Compact Guardlogix 5380 Sil 3 | - |
| Rockwellautomation | Compactlogix 5480 Firmware | >= 32.011, < 33.017 |
| Rockwellautomation | Compactlogix 5480 | - |
| Rockwellautomation | Factorytalk Logix Echo Firmware | >= 33.011, < 34.014 |
| Rockwellautomation | Factorytalk Logix Echo | - |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2024-6207?
CVE-2024-6207 is a vulnerability with a CVSS score of 7.5 (HIGH). CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and send a specially crafted CIP message to the device. If exploited, a threat actor cou...
How severe is CVE-2024-6207?
CVE-2024-6207 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-6207?
Check the references section above for vendor advisories and patch information. Affected products include: Rockwellautomation Controllogix 5580 Firmware, Rockwellautomation Controllogix 5580, Rockwellautomation Controllogix 5580 Process Firmware, Rockwellautomation Controllogix 5580 Process, Rockwellautomation Guardlogix 5580 Firmware.