HIGH · 7.5

CVE-2024-6207

CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html  and send a specially crafted CIP message to the device. If exploited, a threat actor cou...

Vulnerability Description

CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html  and send a specially crafted CIP message to the device. If exploited, a threat actor could help prevent access to the legitimate user and end connections to connected devices including the workstation. To recover the controllers, a download is required which ends any process that the controller is running.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
RockwellautomationControllogix 5580 Firmware>= 28.011, < 33.017
RockwellautomationControllogix 5580-
RockwellautomationControllogix 5580 Process Firmware>= 33.011, < 33.017
RockwellautomationControllogix 5580 Process-
RockwellautomationGuardlogix 5580 Firmware>= 31.011, < 33.017
RockwellautomationGuardlogix 5580-
RockwellautomationCompactlogix 5380 Firmware>= 28.011, < 33.017
RockwellautomationCompactlogix 5380-
RockwellautomationCompact Guardlogix 5380 Sil 2 Firmware>= 31.011, < 33.017
RockwellautomationCompact Guardlogix 5380 Sil 2-
RockwellautomationCompact Guardlogix 5380 Sil 3 Firmware>= 32.013, < 33.017
RockwellautomationCompact Guardlogix 5380 Sil 3-
RockwellautomationCompactlogix 5480 Firmware>= 32.011, < 33.017
RockwellautomationCompactlogix 5480-
RockwellautomationFactorytalk Logix Echo Firmware>= 33.011, < 34.014
RockwellautomationFactorytalk Logix Echo-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-6207?

CVE-2024-6207 is a vulnerability with a CVSS score of 7.5 (HIGH). CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html  and send a specially crafted CIP message to the device. If exploited, a threat actor cou...

How severe is CVE-2024-6207?

CVE-2024-6207 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-6207?

Check the references section above for vendor advisories and patch information. Affected products include: Rockwellautomation Controllogix 5580 Firmware, Rockwellautomation Controllogix 5580, Rockwellautomation Controllogix 5580 Process Firmware, Rockwellautomation Controllogix 5580 Process, Rockwellautomation Guardlogix 5580 Firmware.