CVE-2024-5659: Rockwell Automation Multicast Request Causes major nonrecoverable fault on Select Controllers

Published Jun 14, 2024
·
Updated

Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result in a major nonrecoverable fault(MNRF/Assert). This vulnerability could be exploited by sending abnormal packets to the mDNS port. If exploited, the availability of the device would be compromised.

Affected Software

13 affected components
Rockwell Automation Select Controllers
All of the following
rockwellautomation Controllogix 5580 Firmware=34.011
rockwellautomation Controllogix 5580
All of the following
rockwellautomation Guardlogix 5580 Firmware=34.011
rockwellautomation Guardlogix 5580
All of the following
rockwellautomation 1756-en4 Firmware=4.001
rockwellautomation 1756-en4
All of the following
rockwellautomation Compactlogix 5380 Firmware=34.011
rockwellautomation Compactlogix 5380
All of the following
rockwellautomation Compact Guardlogix 5380 Firmware=34.011
rockwellautomation Compact Guardlogix 5380
All of the following
rockwellautomation Compactlogix 5480 Firmware=34.011
rockwellautomation Compactlogix 5480

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Rockwell Automation Compact GuardLogix 5380 / CompactLogix 5380 / CompactLogix 5480 / ControlLogix 5580 to a version that resolves this vulnerability.

    Fixed in V34.014, V35.013, V36.011 and later
  2. Upgrade

    Upgrade Rockwell Automation GuardLogix 5580 to a version that resolves this vulnerability.

    Fixed in V6.001 and later
  3. Compensating control

    Apply risk mitigations where possible to address the vulnerability where abnormal packets sent to the mDNS port can cause major nonrecoverable fault (MNRF/Assert) on affected controllers on the same network.

Event History

Jun 14, 2024
CVE Published
via MITRE·04:42 PM
Data Sourced
via MITRE·04:42 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-5659?

CVE-2024-5659 is classified as a critical vulnerability due to its potential to cause major nonrecoverable faults in affected Rockwell Automation controllers.

2

How do I fix CVE-2024-5659?

To mitigate CVE-2024-5659, immediately apply the recommended software updates and patches provided by Rockwell Automation for the Select Controllers.

3

Which products are affected by CVE-2024-5659?

CVE-2024-5659 affects Rockwell Automation Select Controllers on the same network.

4

What is the impact of CVE-2024-5659 if exploited?

Exploitation of CVE-2024-5659 could lead to a significant availability impact, resulting in controllers experiencing a major nonrecoverable fault.

5

Can CVE-2024-5659 be remotely exploited?

Yes, CVE-2024-5659 can be exploited remotely by sending abnormal packets to the mDNS port of the affected controllers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203