First published: Wed Aug 14 2024(Updated: )
CVE-2024-7515 IMPACT A denial-of-service vulnerability exists in the affected products. A malformed PTP management packet can cause a major nonrecoverable fault in the controller.
Credit: PSIRT@rockwellautomation.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rockwell Automation GuardLogix 5580 | ||
Rockwell Automation Compact GuardLogix 5380 SIL 3 | ||
All of | ||
Any of | ||
Rockwell Automation CompactLogix 5380 Firmware | >=28.011<34.014 | |
Rockwell Automation CompactLogix 5380 Firmware | =35.011 | |
Rockwell Automation CompactLogix 5380 Firmware | ||
All of | ||
Any of | ||
Rockwell Automation ControlLogix 5580 Firmware | >=28.011<34.014 | |
Rockwell Automation ControlLogix 5580 Firmware | =35.011 | |
Rockwell Automation ControlLogix 5580 Firmware | ||
All of | ||
Any of | ||
Rockwell Automation GuardLogix 5580 Firmware | >=31.011<34.014 | |
Rockwell Automation GuardLogix 5580 Firmware | =35.011 | |
Rockwell Automation GuardLogix 5580 | ||
All of | ||
Any of | ||
rockwellautomation Compact GuardLogix 5380 sil 2 | >=31.011<34.014 | |
rockwellautomation Compact GuardLogix 5380 sil 2 | =35.011 | |
Compact GuardLogix 5380 SIL 2 Firmware | ||
All of | ||
Any of | ||
Rockwell Automation Compact GuardLogix 5380 SIL 3 Firmware | >=32.013<34.014 | |
Rockwell Automation Compact GuardLogix 5380 SIL 3 Firmware | =35.011 | |
Rockwell Automation Compact GuardLogix 5380 SIL 3 | ||
All of | ||
Any of | ||
Rockwell Automation CompactLogix 5480 Firmware | >=32.011<34.014 | |
Rockwell Automation CompactLogix 5480 Firmware | =35.011 | |
Rockwell Automation CompactLogix 5480 |
Upgrade to: v36.011, v35.013, v34.014
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-7515 has a high severity due to its potential to cause a denial-of-service condition.
To fix CVE-2024-7515, ensure that your Rockwell Automation ControlLogix/GuardLogix 5580 or CompactLogix/Compact GuardLogix 5380 devices are updated to the latest firmware version provided by Rockwell Automation.
CVE-2024-7515 affects Rockwell Automation ControlLogix/GuardLogix 5580 and CompactLogix/Compact GuardLogix 5380 products.
CVE-2024-7515 is categorized as a denial-of-service vulnerability caused by a malformed PTP management packet.
While CVE-2024-7515 primarily leads to a denial-of-service situation, it can result in temporary loss of control of the affected system.