Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-8626


Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multiple actions on certain web pages of the product causing the affected products to become fully unavailable and require a power cycle to recover.


Published

2024-10-08T17:15:56.240

Last Modified

2025-02-27T19:30:07.490

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-400
  • Type: Primary
    CWE-401

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System rockwellautomation compactlogix_5380_firmware < 33.015 Yes
Hardware rockwellautomation compactlogix_5380 - No
Operating System rockwellautomation compact_guardlogix_5380_firmware < 33.015 Yes
Hardware rockwellautomation compact_guardlogix_5380 - No
Operating System rockwellautomation compactlogix_5480_firmware < 33.015 Yes
Hardware rockwellautomation compactlogix_5480 - No
Operating System rockwellautomation controllogix_5580_firmware < 33.015 Yes
Hardware rockwellautomation controllogix_5580 - No
Operating System rockwellautomation guardlogix_5580_firmware < 33.015 Yes
Hardware rockwellautomation guardlogix_5580 - No
Operating System rockwellautomation 1756-en4tr_firmware 3.002 Yes
Hardware rockwellautomation 1756-en4tr - No

References