CVE-2024-40619: Rockwell Automation GuardLogix/ControlLogix 5580 Controller denial-of-service Vulnerability via Malformed Packet Handling
CVE-2024-40619 IMPACT
A denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a malformed CIP packet is sent over the network to the device and results in a major nonrecoverable fault causing a denial-of-service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40619?
CVE-2024-40619 is classified as a denial-of-service vulnerability that can lead to a major nonrecoverable fault.
How do I fix CVE-2024-40619?
To mitigate CVE-2024-40619, it is essential to apply the latest firmware updates provided by Rockwell Automation for affected devices.
What products are affected by CVE-2024-40619?
CVE-2024-40619 affects the Rockwell Automation GuardLogix/ControlLogix 5580 Controller and specific firmware versions.
What causes the denial-of-service in CVE-2024-40619?
The denial-of-service in CVE-2024-40619 is triggered by the receipt of a malformed CIP packet sent to the device.
Is there a workaround for CVE-2024-40619?
Currently, the recommended approach to address CVE-2024-40619 is to ensure device firmware is updated to the latest version.