CVE-2024-5659: Rockwell Automation Multicast Request Causes major nonrecoverable fault on Select Controllers
Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result in a major nonrecoverable fault(MNRF/Assert). This vulnerability could be exploited by sending abnormal packets to the mDNS port. If exploited, the availability of the device would be compromised.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Rockwell Automation Compact GuardLogix 5380 / CompactLogix 5380 / CompactLogix 5480 / ControlLogix 5580to a version that resolves this vulnerability.Fixed in V34.014, V35.013, V36.011 and later - Upgrade
Upgrade
Rockwell Automation GuardLogix 5580to a version that resolves this vulnerability.Fixed in V6.001 and later - Compensating control
Apply risk mitigations where possible to address the vulnerability where abnormal packets sent to the mDNS port can cause major nonrecoverable fault (MNRF/Assert) on affected controllers on the same network.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5659?
CVE-2024-5659 is classified as a critical vulnerability due to its potential to cause major nonrecoverable faults in affected Rockwell Automation controllers.
How do I fix CVE-2024-5659?
To mitigate CVE-2024-5659, immediately apply the recommended software updates and patches provided by Rockwell Automation for the Select Controllers.
Which products are affected by CVE-2024-5659?
CVE-2024-5659 affects Rockwell Automation Select Controllers on the same network.
What is the impact of CVE-2024-5659 if exploited?
Exploitation of CVE-2024-5659 could lead to a significant availability impact, resulting in controllers experiencing a major nonrecoverable fault.
Can CVE-2024-5659 be remotely exploited?
Yes, CVE-2024-5659 can be exploited remotely by sending abnormal packets to the mDNS port of the affected controllers.