CVE-2024-6207: Input Validation
CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and send a specially crafted CIP message to the device. If exploited, a threat actor could help prevent access to the legitimate user and end connections to connected devices including the workstation. To recover the controllers, a download is required which ends any process that the controller is running.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6207?
CVE-2024-6207 is classified as a critical vulnerability that allows a threat actor to disrupt access to connected devices.
How do I fix CVE-2024-6207?
To remediate CVE-2024-6207, update the affected Rockwell Automation ControlLogix firmware to the latest versions listed in the advisory.
What software is affected by CVE-2024-6207?
CVE-2024-6207 affects various versions of Rockwell Automation ControlLogix, GuardLogix, CompactLogix, and related firmware.
What could happen if CVE-2024-6207 is exploited?
Exploitation of CVE-2024-6207 may allow an attacker to prevent legitimate user access and terminate connections to affected devices.
Is there a workaround for CVE-2024-6207?
Currently, there are no public workarounds for CVE-2024-6207; updating the firmware is the recommended action.