CVE-2024-6077: Rockwell Automation ControlLogix/GuardLogix 5580 and CompactLogix/Compact GuardLogix® 5380 Vulnerable to DoS vulnerability via CIP
A denial-of-service vulnerability exists in the Rockwell Automation affected products when specially crafted packets are sent to the CIP Security Object. If exploited the device will become unavailable and require a factory reset to recover.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6077?
CVE-2024-6077 has a high severity rating due to its potential to cause denial-of-service conditions.
How do I fix CVE-2024-6077?
To mitigate CVE-2024-6077, upgrade the affected Rockwell Automation products to the latest firmware version provided by the vendor.
What types of products are affected by CVE-2024-6077?
CVE-2024-6077 affects various Rockwell Automation products including CompactLogix 5380, GuardLogix 5380, and ControlLogix 5580 among others.
What happens if CVE-2024-6077 is exploited?
If exploited, CVE-2024-6077 can render the device unavailable, requiring a factory reset for recovery.
Are all Rockwell Automation devices vulnerable to CVE-2024-6077?
No, only specific versions of Rockwell Automation devices are vulnerable to CVE-2024-6077.