CVE-2024-21916: Rockwell Automation Denial-of-service Vulnerability in ICE1 Controller
A denial-of-service vulnerability exists in specific Rockwell Automation ControlLogix ang GuardLogix controllers. If exploited, the product could potentially experience a major nonrecoverable fault (MNRF). The device will restart itself to recover from the MNRF.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Rockwell Automation ControlLogix 5570 / GuardLogix 5570 firmwareto a version that resolves this vulnerability.Fixed in 20.011 - Upgrade
Upgrade
Rockwell Automation ControlLogix 5570 / GuardLogix 5570 firmwareto a version that resolves this vulnerability.Fixed in 20.054_kit1 - Upgrade
Upgrade
Rockwell Automation ControlLogix 5570 / GuardLogix 5570 firmwareto a version that resolves this vulnerability.Fixed in v33.016 - Upgrade
Upgrade
Rockwell Automation ControlLogix 5570 / GuardLogix 5570 firmwareto a version that resolves this vulnerability.Fixed in v33.053_kit1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21916?
CVE-2024-21916 is classified as a denial-of-service vulnerability with the potential for significant impact due to major nonrecoverable faults.
How do I fix CVE-2024-21916?
To mitigate CVE-2024-21916, it is advised to update the firmware of affected Rockwell Automation ControlLogix and GuardLogix controllers.
Which devices are affected by CVE-2024-21916?
CVE-2024-21916 affects specific Rockwell Automation ControlLogix and GuardLogix controllers running firmware versions 20.011 and 20.054_kit1.
What could happen if CVE-2024-21916 is exploited?
Exploitation of CVE-2024-21916 could lead to major nonrecoverable faults, causing the device to restart and potentially disrupting operations.
Who should be concerned about CVE-2024-21916?
Users and administrators of Rockwell Automation ControlLogix and GuardLogix controllers should pay attention to CVE-2024-21916 due to its potential impact on system reliability.