CVE-2024-6089: Rockwell Automation Major nonrecoverable fault in 5015 – AENFTXT
An input validation vulnerability exists in the Rockwell Automation 5015 - AENFTXT when a manipulated PTP packet is sent, causing the secondary adapter to result in a major nonrecoverable fault. If exploited, a power cycle is required to recover the product.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Rockwell Automation 5015 - AENFTXTto a version that resolves this vulnerability.Fixed in v2.012 - Compensating control
Implement Rockwell Automation suggested security best practices for industrial automation control systems to minimize the risk of the input validation vulnerability in 5015 – AENFTXT.
- Operational
If the vulnerability is exploited, perform a power cycle to recover the product.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6089?
The severity of CVE-2024-6089 is classified as critical due to the potential for a major nonrecoverable fault when exploited.
How do I fix CVE-2024-6089?
To fix CVE-2024-6089, you need to ensure that your Rockwell Automation 5015 - AENFTXT firmware is updated to the latest version available.
What causes the vulnerability CVE-2024-6089?
CVE-2024-6089 is caused by improper input validation in the Rockwell Automation 5015 - AENFTXT when processing manipulated PTP packets.
What happens if CVE-2024-6089 is exploited?
If CVE-2024-6089 is exploited, it can lead to a major nonrecoverable fault that requires a power cycle to recover the device.
Which versions of the software are affected by CVE-2024-6089?
CVE-2024-6089 affects Rockwell Automation 5015 - AENFTXT firmware version 2.011.