Rockwell Automation Logix Controllers Uncontrolled Resource Consumption
Published May 31, 2022
8.6
HIGHCVSS 3.1
EPSS 2.13%
Description
A malformed Class 3 common industrial protocol message with a cached connection can cause a denial-of-service condition in Rockwell Automation Logix Controllers, resulting in a major nonrecoverable fault. If the target device becomes unavailable, a user would have to clear the fault and redownload the user project file to bring the device back online.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<=33.013
- Version
-
- Version unspecifiedStatusaffectedConstraints<=32.013
- Version
-
- Version unspecifiedStatusaffectedConstraints<=33.013
- Version
-
- Version unspecifiedStatusaffectedConstraints<=32.013
- Version
-
- Version unspecifiedStatusaffectedConstraints<=32.013
- Version
-
- Version unspecifiedStatusaffectedConstraints<=33.013
- Version
-
- Version unspecifiedStatusaffectedConstraints<=32.013
- Version
-
- Version 33.013StatusaffectedConstraints-
- Version
-
- Version unspecifiedStatusaffectedConstraints<=32.013
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Rockwell Automation | Compact GuardLogix 5370 controllers | n/a |
| ||||||
| Rockwell Automation | Compact GuardLogix 5380 controllers | n/a |
| ||||||
| Rockwell Automation | CompactLogix 5370 controllers | n/a |
| ||||||
| Rockwell Automation | CompactLogix 5380 controllers | n/a |
| ||||||
| Rockwell Automation | CompactLogix 5480 controllers | n/a |
| ||||||
| Rockwell Automation | ControlLogix 5570 controllers | n/a |
| ||||||
| Rockwell Automation | ControlLogix 5580 controllers | n/a |
| ||||||
| Rockwell Automation | GuardLogix 5570 controllers | n/a |
| ||||||
| Rockwell Automation | GuardLogix 5580 controllers | n/a |
|
Configuration 1
- < 33.011
Running on/with
- n/a
Configuration 2
- < 33.011
Running on/with
- n/a
Configuration 3
- < 33.011
Running on/with
- n/a
Configuration 4
- < 33.011
Running on/with
- n/a
Configuration 5
- < 33.011
Running on/with
- n/a
Configuration 6
- < 34.011
Running on/with
- n/a
Configuration 7
- < 34.011
Running on/with
- n/a
Configuration 8
- < 34.011
Running on/with
- n/a
Configuration 9
- < 34.011
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Rockwell Automation recommends users update to the latest firmware version to mitigate this vulnerability. Users are directed towards the risk mitigation provided below and are encouraged (where possible) to combine these with the general security guidelines below to employ multiple strategies simultaneously. Users should go to Rockwell Automation's Product Compatibility & Download Center to download the latest firmware.
CompactLogix 5380, Compact GuardLogix 5380, CompactLogix 5480, ControlLogix 5580, GuardLogix 5580: Upgrade to v33.011 firmware CompactLogix 5370, Compact GuardLogix 5370, ControlLogix 5570, GuardLogix 5570: Upgrade to v34.011 firmware
Please see Rockwell Automation’s security advisory PN1596 for more information. https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1135559
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-25077 Advisory
- https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1135559 x_refsource_CONFIRMPermissions RequiredVendor Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-144-01 x_refsource_CONFIRMThird Party AdvisoryUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-25077 | Advisory | |
| https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1135559 | x_refsource_CONFIRMPermissions RequiredVendor Advisory | |
| https://www.cisa.gov/uscert/ics/advisories/icsa-22-144-01 | x_refsource_CONFIRMThird Party AdvisoryUS Government Resource |
Change history (0)
No recorded changes yet.