CVE-2018-19282: Critical severity rockwellautomation Powerflex 525 Ac Drives Firmware vulnerability
Rockwell Automation PowerFlex 525 AC Drives 5.001 and earlier allow remote attackers to cause a denial of service by crashing the Common Industrial Protocol (CIP) network stack. The vulnerability allows the attacker to crash the CIP in a way that it does not accept new connections, but keeps the current connections active, which can prevent legitimate users from recovering control.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-19282?
CVE-2018-19282 has been classified as a medium severity vulnerability.
How do I fix CVE-2018-19282?
To mitigate CVE-2018-19282, update the Rockwell Automation PowerFlex 525 AC Drives firmware to version 5.002 or later.
What systems are affected by CVE-2018-19282?
CVE-2018-19282 affects Rockwell Automation PowerFlex 525 AC Drives with firmware versions up to and including 5.001.
What type of attack does CVE-2018-19282 allow?
CVE-2018-19282 allows remote attackers to cause a denial of service by crashing the Common Industrial Protocol (CIP) network stack.
Can CVE-2018-19282 be exploited remotely?
Yes, CVE-2018-19282 can be exploited remotely by attackers targeting the vulnerable CIP network stack.