CVE-2024-3493: Rockwell Automation ControlLogix and GaurdLogix Vulnerable to Major Nonrecoverable Fault Due to Invalid Header Value

Published Apr 15, 2024
·
Updated

A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause a major nonrecoverable fault (MNRF) Rockwell Automation's ControlLogix 5580, Guard Logix 5580, CompactLogix 5380, and 1756-EN4TR. If exploited, the affected product will become unavailable and require a manual restart to recover it. Additionally, an MNRF could result in a loss of view and/or control of connected devices.

Affected Software

20 affected components
Rockwell Automation ControlLogix 5580
Rockwell Automation Guard Logix 5580
Rockwell Automation CompactLogix 5380
Rockwell Automation 1756-EN4TR
All of the following
rockwellautomation Controllogix 5580 Firmware=35.011
rockwellautomation Controllogix 5580
All of the following
rockwellautomation Guardlogix 5580 Firmware=35.011
rockwellautomation Guardlogix 5580
All of the following
rockwellautomation Compactlogix 5380 Firmware=35.011
rockwellautomation Compactlogix 5380
All of the following
rockwellautomation Compact Guardlogix 5380 Firmware=35.011
rockwellautomation Compact Guardlogix 5380
All of the following
rockwellautomation 1756-en4tr Firmware=5.001
rockwellautomation 1756-en4tr
All of the following
rockwellautomation Controllogix 5580 Process Firmware=35.011
rockwellautomation Controllogix 5580 Process
All of the following
rockwellautomation Compactlogix 5380 Process Firmware=35.011
rockwellautomation Compactlogix 5380 Process
All of the following
rockwellautomation Compactlogix 5480 Firmware=35.011
rockwellautomation Compactlogix 5480

Remediation

Information

Affected Product         First Known in Firmware Revision         Corrected in Firmware Revision         ControlLogix® 5580         V35.011         V35.013, V36.011         GuardLogix 5580         V35.011         V35.013, V36.011         CompactLogix 5380         V35.011         V35.013, V36.011         1756-EN4TR         V5.001         V6.001     Users using the affected software and who are not able to upgrade to one of the corrected versions are encouraged to apply security best practices, where possible.   * Security Best Practices https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight  

Event History

Apr 15, 2024
CVE Published
via MITRE·09:17 PM
Data Sourced
via MITRE·09:17 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-3493?

CVE-2024-3493 is classified with a major nonrecoverable fault that could lead to significant operational disruptions.

2

How do I fix CVE-2024-3493?

To mitigate CVE-2024-3493, apply the latest firmware updates provided by Rockwell Automation to affected devices.

3

Which devices are affected by CVE-2024-3493?

CVE-2024-3493 affects Rockwell Automation's ControlLogix 5580, GuardLogix 5580, CompactLogix 5380, and 1756-EN4TR devices.

4

What should I do if my system is impacted by CVE-2024-3493?

If your system is impacted by CVE-2024-3493, immediately update your firmware and consider network segmentation to limit exposure.

5

Is there a known exploit for CVE-2024-3493?

Currently, there are no publicly known exploits for CVE-2024-3493, but it is advised to take preventative measures.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203