CVE-2024-7507
Severity CVSS v4.0:
HIGH
Type:
CWE-20
Input Validation
Publication date:
14/08/2024
Last modified:
04/03/2025
Description
CVE-2024-7507 IMPACT<br />
<br />
A denial-of-service vulnerability exists in the affected products. This vulnerability occurs when a malformed PCCC message is received, causing a fault in the controller.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:rockwellautomation:compactlogix_5380_firmware:*:*:*:*:*:*:*:* | 28.011 (including) | 34.014 (excluding) |
| cpe:2.3:o:rockwellautomation:compactlogix_5380_firmware:35.011:*:*:*:*:*:*:* | ||
| cpe:2.3:h:rockwellautomation:compactlogix_5380:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:rockwellautomation:controllogix_5580_firmware:*:*:*:*:*:*:*:* | 28.011 (including) | 34.014 (excluding) |
| cpe:2.3:o:rockwellautomation:controllogix_5580_firmware:35.011:*:*:*:*:*:*:* | ||
| cpe:2.3:h:rockwellautomation:controllogix_5580:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:rockwellautomation:guardlogix_5580_firmware:*:*:*:*:*:*:*:* | 31.011 (including) | 34.014 (excluding) |
| cpe:2.3:o:rockwellautomation:guardlogix_5580_firmware:35.011:*:*:*:*:*:*:* | ||
| cpe:2.3:h:rockwellautomation:guardlogix_5580:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:rockwellautomation:compact_guardlogix_5380_sil_2_firmware:*:*:*:*:*:*:*:* | 31.011 (including) | 34.014 (excluding) |
| cpe:2.3:o:rockwellautomation:compact_guardlogix_5380_sil_2_firmware:35.011:*:*:*:*:*:*:* | ||
| cpe:2.3:h:rockwellautomation:compact_guardlogix_5380_sil_2:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:rockwellautomation:compact_guardlogix_5380_sil_3_firmware:*:*:*:*:*:*:*:* | 32.013 (including) | 34.014 (excluding) |
| cpe:2.3:o:rockwellautomation:compact_guardlogix_5380_sil_3_firmware:35.011:*:*:*:*:*:*:* | ||
| cpe:2.3:h:rockwellautomation:compact_guardlogix_5380_sil_3:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



