CVE-2024-3493: Rockwell Automation ControlLogix and GaurdLogix Vulnerable to Major Nonrecoverable Fault Due to Invalid Header Value
A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause a major nonrecoverable fault (MNRF) Rockwell Automation's ControlLogix 5580, Guard Logix 5580, CompactLogix 5380, and 1756-EN4TR. If exploited, the affected product will become unavailable and require a manual restart to recover it. Additionally, an MNRF could result in a loss of view and/or control of connected devices.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3493?
CVE-2024-3493 is classified with a major nonrecoverable fault that could lead to significant operational disruptions.
How do I fix CVE-2024-3493?
To mitigate CVE-2024-3493, apply the latest firmware updates provided by Rockwell Automation to affected devices.
Which devices are affected by CVE-2024-3493?
CVE-2024-3493 affects Rockwell Automation's ControlLogix 5580, GuardLogix 5580, CompactLogix 5380, and 1756-EN4TR devices.
What should I do if my system is impacted by CVE-2024-3493?
If your system is impacted by CVE-2024-3493, immediately update your firmware and consider network segmentation to limit exposure.
Is there a known exploit for CVE-2024-3493?
Currently, there are no publicly known exploits for CVE-2024-3493, but it is advised to take preventative measures.