First published: Thu Apr 04 2019(Updated: )
Rockwell Automation PowerFlex 525 AC Drives 5.001 and earlier allow remote attackers to cause a denial of service by crashing the Common Industrial Protocol (CIP) network stack. The vulnerability allows the attacker to crash the CIP in a way that it does not accept new connections, but keeps the current connections active, which can prevent legitimate users from recovering control.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Rockwell Automation PowerFlex 525 AC Drives Firmware | <=5.001 | |
Rockwell Automation PowerFlex 525 AC Drives Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19282 has been classified as a medium severity vulnerability.
To mitigate CVE-2018-19282, update the Rockwell Automation PowerFlex 525 AC Drives firmware to version 5.002 or later.
CVE-2018-19282 affects Rockwell Automation PowerFlex 525 AC Drives with firmware versions up to and including 5.001.
CVE-2018-19282 allows remote attackers to cause a denial of service by crashing the Common Industrial Protocol (CIP) network stack.
Yes, CVE-2018-19282 can be exploited remotely by attackers targeting the vulnerable CIP network stack.