Description
Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result in a major nonrecoverable fault(MNRF/Assert). This vulnerability could be exploited by sending abnormal packets to the mDNS port. If exploited, the availability of the device would be compromised.
Scores
CVSS v3
6.5
EPSS
0.0041
EPSS Percentile
61.4%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-670
Status
published
Products (6)
rockwellautomation/1756-en4_firmware
4.001
rockwellautomation/compact_guardlogix_5380_firmware
34.011
rockwellautomation/compactlogix_5380_firmware
34.011
rockwellautomation/compactlogix_5480_firmware
34.011
rockwellautomation/controllogix_5580_firmware
34.011
rockwellautomation/guardlogix_5580_firmware
34.011
Published
Jun 14, 2024
Tracked Since
Feb 18, 2026