CVE-2017-6024

A Resource Exhaustion issue was discovered in Rockwell Automation ControlLogix 5580 controllers V28.011, V28.012, and V28.013; ControlLogix 5580 controllers V29.011; CompactLogix 5380 controllers V28.011; and CompactLogix 5380 controllers V29.011. This vulnerability may allow an attacker to cause a denial of service condition by sending a series of specific CIP-based commands to the controller.
References
Link Resource
http://www.securityfocus.com/bid/98309 Third Party Advisory VDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-17-094-05 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:rockwellautomation:compactlogix_5380_firmware:v28.011:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:compactlogix_5380_firmware:v29.011:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:compactlogix_5380:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:rockwellautomation:controllogix_5580_firmware:v28.011:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:controllogix_5580_firmware:v28.012:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:controllogix_5580_firmware:v28.013:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:controllogix_5580_firmware:v29.011:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:controllogix_5580:-:*:*:*:*:*:*:*

History

23 Mar 2022, 14:09

Type Values Removed Values Added
First Time Rockwellautomation compactlogix 5380 Firmware
Rockwellautomation compactlogix 5380
CPE cpe:2.3:h:rockwellautomation:compactlogix_5830:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:compactlogix_5830_firmware:v28.011:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:compactlogix_5830_firmware:v29.011:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:compactlogix_5380:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:compactlogix_5380_firmware:v28.011:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:compactlogix_5380_firmware:v29.011:*:*:*:*:*:*:*

Information

Published : 2017-05-06 00:29

Updated : 2023-12-10 12:01


NVD link : CVE-2017-6024

Mitre link : CVE-2017-6024

CVE.ORG link : CVE-2017-6024


JSON object : View

Products Affected

rockwellautomation

  • controllogix_5580
  • controllogix_5580_firmware
  • compactlogix_5380
  • compactlogix_5380_firmware
CWE
CWE-400

Uncontrolled Resource Consumption