// For flags

CVE-2024-21916

Rockwell Automation Denial-of-service Vulnerability in ICE1 Controller

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Attend
*SSVC
Descriptions

A denial-of-service vulnerability exists in specific Rockwell Automation ControlLogix ang GuardLogix controllers. If exploited, the product could potentially experience a major nonrecoverable fault (MNRF). The device will restart itself to recover from the MNRF.

Existe una vulnerabilidad de denegación de servicio en controladores Rockwell Automation ControlLogix ang GuardLogix. Si se explota, el producto podría experimentar un fallo importante no recuperable (MNRF). El dispositivo se reiniciará solo para recuperarse del MNRF.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
None
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:Attend
Exploitation
None
Automatable
Yes
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2024-01-03 CVE Reserved
  • 2024-01-31 CVE Published
  • 2024-02-08 EPSS Updated
  • 2024-08-01 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
  • CAPEC-100: Overflow Buffers
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Rockwellautomation
Search vendor "Rockwellautomation"
Controllogix 5570 Controller Firmware
Search vendor "Rockwellautomation" for product "Controllogix 5570 Controller Firmware"
20.011
Search vendor "Rockwellautomation" for product "Controllogix 5570 Controller Firmware" and version "20.011"
-
Affected
in Rockwellautomation
Search vendor "Rockwellautomation"
Controllogix 5570 Controller
Search vendor "Rockwellautomation" for product "Controllogix 5570 Controller"
--
Safe
Rockwellautomation
Search vendor "Rockwellautomation"
Guardlogix 5570 Controller Firmware
Search vendor "Rockwellautomation" for product "Guardlogix 5570 Controller Firmware"
20.011
Search vendor "Rockwellautomation" for product "Guardlogix 5570 Controller Firmware" and version "20.011"
-
Affected
in Rockwellautomation
Search vendor "Rockwellautomation"
Guardlogix 5570 Controller
Search vendor "Rockwellautomation" for product "Guardlogix 5570 Controller"
--
Safe
Rockwellautomation
Search vendor "Rockwellautomation"
Controllogix 5570 Redundant Controller Firmware
Search vendor "Rockwellautomation" for product "Controllogix 5570 Redundant Controller Firmware"
20.054_kit1
Search vendor "Rockwellautomation" for product "Controllogix 5570 Redundant Controller Firmware" and version "20.054_kit1"
-
Affected
in Rockwellautomation
Search vendor "Rockwellautomation"
Controllogix 5570 Redundant Controller
Search vendor "Rockwellautomation" for product "Controllogix 5570 Redundant Controller"
--
Safe