Rockwell Automation CompactLogix 5370
cpe:2.3:h:rockwellautomation:compactlogix_5370:*:*:*:*:*:*:*, +7 more
- <= 34.013
- <= 35.012
- <= 36.011
A denial-of-service vulnerability has been identified in Rockwell Automation's CompactLogix 5370 controllers, all software versions through 34.013, 35.012 and 36.011. The issue arises when a malformed CIP forward open message is sent, leading to a major non-recoverable fault that requires a restart to resolve.
Exploitation of this vulnerability causes a significant non-recoverable fault, requiring a restart to recover the affected system.
Users can upgrade to versions 37.011 and later, or versions 34.016, 35.015, or 36.012. For those unable to upgrade, Rockwell Automation recommends following their security best practices.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.