CVE-2024-3493
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
15/04/2024
Last modified:
04/03/2025
Description
<br />
A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause a major nonrecoverable fault (MNRF) Rockwell Automation&#39;s ControlLogix 5580, Guard Logix 5580, CompactLogix 5380, and 1756-EN4TR. If exploited, the affected product will become unavailable and require a manual restart to recover it. Additionally, an MNRF could result in a loss of view and/or control of connected devices. <br />
<br />
Impact
Base Score 3.x
8.60
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:rockwellautomation:controllogix_5580_firmware:35.011:*:*:*:*:*:*:* | ||
| cpe:2.3:h:rockwellautomation:controllogix_5580:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:rockwellautomation:guardlogix_5580_firmware:35.011:*:*:*:*:*:*:* | ||
| cpe:2.3:h:rockwellautomation:guardlogix_5580:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:rockwellautomation:compactlogix_5380_firmware:35.011:*:*:*:*:*:*:* | ||
| cpe:2.3:h:rockwellautomation:compactlogix_5380:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:rockwellautomation:compact_guardlogix_5380_firmware:35.011:*:*:*:*:*:*:* | ||
| cpe:2.3:h:rockwellautomation:compact_guardlogix_5380:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:rockwellautomation:1756-en4tr_firmware:5.001:*:*:*:*:*:*:* | ||
| cpe:2.3:h:rockwellautomation:1756-en4tr:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:rockwellautomation:controllogix_5580_process_firmware:35.011:*:*:*:*:*:*:* | ||
| cpe:2.3:h:rockwellautomation:controllogix_5580_process:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:rockwellautomation:compactlogix_5380_process_firmware:35.011:*:*:*:*:*:*:* | ||
| cpe:2.3:h:rockwellautomation:compactlogix_5380_process:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:rockwellautomation:compactlogix_5480_firmware:35.011:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



