CVE-2024-6207
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
14/10/2024
Last modified:
21/10/2024
Description
CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and send a specially crafted CIP message to the device. If exploited, a threat actor could help prevent access to the legitimate user and end connections to connected devices including the workstation. To recover the controllers, a download is required which ends any process that the controller is running.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:rockwellautomation:controllogix_5580_firmware:*:*:*:*:*:*:*:* | 28.011 (including) | 33.017 (excluding) |
| cpe:2.3:o:rockwellautomation:controllogix_5580_firmware:*:*:*:*:*:*:*:* | 34.011 (including) | 34.014 (excluding) |
| cpe:2.3:o:rockwellautomation:controllogix_5580_firmware:*:*:*:*:*:*:*:* | 35.011 (including) | 35.013 (excluding) |
| cpe:2.3:h:rockwellautomation:controllogix_5580:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:rockwellautomation:controllogix_5580_process_firmware:*:*:*:*:*:*:*:* | 33.011 (including) | 33.017 (excluding) |
| cpe:2.3:o:rockwellautomation:controllogix_5580_process_firmware:*:*:*:*:*:*:*:* | 34.011 (including) | 34.014 (excluding) |
| cpe:2.3:o:rockwellautomation:controllogix_5580_process_firmware:*:*:*:*:*:*:*:* | 35.011 (including) | 35.013 (excluding) |
| cpe:2.3:h:rockwellautomation:controllogix_5580_process:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:rockwellautomation:guardlogix_5580_firmware:*:*:*:*:*:*:*:* | 31.011 (including) | 33.017 (excluding) |
| cpe:2.3:o:rockwellautomation:guardlogix_5580_firmware:*:*:*:*:*:*:*:* | 34.011 (including) | 34.014 (excluding) |
| cpe:2.3:o:rockwellautomation:guardlogix_5580_firmware:*:*:*:*:*:*:*:* | 35.011 (including) | 35.013 (excluding) |
| cpe:2.3:h:rockwellautomation:guardlogix_5580:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:rockwellautomation:compactlogix_5380_firmware:*:*:*:*:*:*:*:* | 28.011 (including) | 33.017 (excluding) |
| cpe:2.3:o:rockwellautomation:compactlogix_5380_firmware:*:*:*:*:*:*:*:* | 34.011 (including) | 34.014 (excluding) |
| cpe:2.3:o:rockwellautomation:compactlogix_5380_firmware:*:*:*:*:*:*:*:* | 35.011 (including) | 35.013 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



