CVE-2024-7507: Rockwell Automation ControlLogix/GuardLogix 5580 and CompactLogix/Compact GuardLogix® 5380 Controller Denial-of-Service Vulnerability via Input Validation
Published Aug 14, 2024
·Updated
CVE-2024-7507 IMPACT
A denial-of-service vulnerability exists in the affected products. This vulnerability occurs when a malformed PCCC message is received, causing a fault in the controller.
Affected Software
20 affected components
Rockwell Automation ControlLogix/GuardLogix 5580
Rockwell Automation CompactLogix/Compact GuardLogix 5380
All of the following
Any of the following
rockwellautomation Compactlogix 5380 Firmware>=28.011<34.014
rockwellautomation Compactlogix 5380 Firmware=35.011
rockwellautomation Compactlogix 5380
All of the following
Any of the following
rockwellautomation Controllogix 5580 Firmware>=28.011<34.014
rockwellautomation Controllogix 5580 Firmware=35.011
rockwellautomation Controllogix 5580
All of the following
Any of the following
rockwellautomation Guardlogix 5580 Firmware>=31.011<34.014
rockwellautomation Guardlogix 5580 Firmware=35.011
rockwellautomation Guardlogix 5580
All of the following
Any of the following
rockwellautomation Compact Guardlogix 5380 Sil 2 Firmware>=31.011<34.014
rockwellautomation Compact Guardlogix 5380 Sil 2 Firmware=35.011
rockwellautomation Compact Guardlogix 5380 Sil 2
All of the following
Any of the following
rockwellautomation Compact Guardlogix 5380 Sil 3 Firmware>=32.013<34.014
rockwellautomation Compact Guardlogix 5380 Sil 3 Firmware=35.011
rockwellautomation Compact Guardlogix 5380 Sil 3
All of the following
Any of the following
rockwellautomation Compactlogix 5480 Firmware>=32.011<34.014
rockwellautomation Compactlogix 5480 Firmware=35.011
rockwellautomation Compactlogix 5480
Remediation
Information
Upgrade to:
v36.011, v35.013, v34.014
Event History
Aug 14, 2024
CVE Published
via MITRE·07:35 PM
Data Sourced
via MITRE·07:35 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-7507?
CVE-2024-7507 is classified as a denial-of-service vulnerability.
2
How does CVE-2024-7507 affect the affected products?
CVE-2024-7507 causes a fault in the controller upon receiving a malformed PCCC message.
3
Which products are impacted by CVE-2024-7507?
CVE-2024-7507 affects Rockwell Automation ControlLogix/GuardLogix 5580 and CompactLogix/Compact GuardLogix 5380.
4
What could be the potential impact of CVE-2024-7507?
The potential impact of CVE-2024-7507 is a denial-of-service condition that disrupts normal operation.
5
How can organizations protect themselves from CVE-2024-7507?
Organizations can protect themselves by applying any provided patches or updates from Rockwell Automation regarding CVE-2024-7507.