CVE-2024-12373: Rockwell Automation PowerMonitor™ 1000 Denial of Service
Published Dec 18, 2024
·Updated
A denial-of-service vulnerability exists in the Rockwell Automation Power Monitor 1000. The vulnerability results in a buffer-overflow, potentially causing denial-of-service.
Affected Software
1 affected component
Rockwell Automation Power Monitor 1000
Remediation
Information
Affected Products
Affected firmware revision
Corrected in firmware revision
PM1k 1408-BC3A-485
<4.020
4.020
PM1k 1408-BC3A-ENT
<4.020
4.020
PM1k 1408-TS3A-485
<4.020
4.020
PM1k 1408-TS3A-ENT
<4.020
4.020
PM1k 1408-EM3A-485
<4.020
4.020
PM1k 1408-EM3A-ENT
<4.020
4.020
PM1k 1408-TR1A-485
<4.020
4.020
PM1k 1408-TR2A-485
<4.020
4.020
PM1k 1408-EM1A-485
<4.020
4.020
PM1k 1408-EM2A-485
<4.020
4.020
PM1k 1408-TR1A-ENT
<4.020
4.020
PM1k 1408-TR2A-ENT
<4.020
4.020
PM1k 1408-EM1A-ENT
<4.020
4.020
PM1k 1408-EM2A-ENT
<4.020
4.020
Mitigations and Workarounds
Users using the affected software, who are not able to upgrade to one of the corrected versions, are encouraged to apply security best practices, where possible.
· Security Best Practices https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight
Event History
Dec 18, 2024
CVE Published
via MITRE·03:38 PM
Data Sourced
via MITRE·03:38 PM
RemedyDescription
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-12373?
CVE-2024-12373 has been classified as a denial-of-service vulnerability.
2
How do I fix CVE-2024-12373?
To fix CVE-2024-12373, you should apply the recommended security patches released by Rockwell Automation.
3
What causes CVE-2024-12373?
CVE-2024-12373 is caused by a buffer overflow in the Rockwell Automation Power Monitor 1000.
4
What are the potential impacts of CVE-2024-12373?
The potential impacts of CVE-2024-12373 include system crashes and service interruptions.
5
Which product is affected by CVE-2024-12373?
CVE-2024-12373 affects the Rockwell Automation Power Monitor 1000.