CVE-2018-19282

CRITICAL

Rockwell Automation PowerFlex 525 AC Drives <5.001 - DoS

Title source: llm
STIX 2.1

Description

Rockwell Automation PowerFlex 525 AC Drives 5.001 and earlier allow remote attackers to cause a denial of service by crashing the Common Industrial Protocol (CIP) network stack. The vulnerability allows the attacker to crash the CIP in a way that it does not accept new connections, but keeps the current connections active, which can prevent legitimate users from recovering control.

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-19-087-01

Scores

CVSS v3 9.8
EPSS 0.0040
EPSS Percentile 60.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-400
Status published
Products (1)
rockwellautomation/powerflex_525_ac_drives_firmware < 5.001
Published Apr 04, 2019
Tracked Since Feb 18, 2026