CVE-2024-5659

MEDIUMCVSS 6.5/10EPSS 0.31%

Last modified

CVE-2024-5659 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result in a major nonrecoverable fault(MNRF/Assert). This vulnerability could be exploited by sending abnormal packets to the mDNS port. If exploited, the availability of the device would be compromised.. EPSS estimates a 0.31% chance of exploitation in the next 30 days.

Description

Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result in a major nonrecoverable fault(MNRF/Assert). This vulnerability could be exploited by sending abnormal packets to the mDNS port. If exploited, the availability of the device would be compromised.

Metrics

Weakness Enumeration

Affected Software

VendorProductVersions
RockwellautomationControllogix 5580 Firmware34.011
RockwellautomationGuardlogix 5580 Firmware34.011
Rockwellautomation1756-En4 Firmware4.001
RockwellautomationCompactlogix 5380 Firmware34.011
RockwellautomationCompact Guardlogix 5380 Firmware34.011
RockwellautomationCompactlogix 5480 Firmware34.011

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2024-5659?
Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result in a major nonrecoverable fault(MNRF/Assert). This vulnerability could be exploited by sending abnormal packets to the mDNS port. If exploited, the availability of the device would be compromised.
How severe is CVE-2024-5659?
CVE-2024-5659 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 0.31% probability of exploitation in the next 30 days.
How do I fix CVE-2024-5659?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2024

Are you affected by CVE-2024-5659?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST