CVE-2024-7567: Rockwell Automation Micro850/870 Vulnerable to denial-of-service Vulnerability via CIP/Modbus Port
Published Aug 13, 2024
·Updated
A denial-of-service vulnerability exists via the CIP/Modbus port in the Rockwell Automation Micro850/870 (2080 -L50E/2080 -L70E). If exploited, the CIP/Modbus communication may be disrupted for short duration.
Affected Software
1 affected component
Rockwell Automation Micro850/870
Remediation
Information
* Update to the corrected version:
v22.011 or later.
Customers using the affected software are encouraged to apply security best practices, if possible.
· For information on how to mitigate Security Risks on industrial automation control systems, we encourage customers to implement our suggested security best practices https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight to minimize the risk of the vulnerability
Event History
Aug 13, 2024
CVE Published
via MITRE·05:51 PM
Data Sourced
via MITRE·05:51 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-7567?
CVE-2024-7567 has been rated as a denial-of-service vulnerability.
2
How do I fix CVE-2024-7567?
To mitigate CVE-2024-7567, apply security updates from Rockwell Automation for the Micro850/870 series.
3
What systems are affected by CVE-2024-7567?
CVE-2024-7567 affects the Rockwell Automation Micro850 and Micro870 controllers.
4
What impact does CVE-2024-7567 have?
Exploitation of CVE-2024-7567 may lead to brief disruptions in CIP/Modbus communication.
5
Is there a workaround for CVE-2024-7567?
Currently, the recommended action is to apply the latest patches and security updates from Rockwell Automation.