CVE-2024-3493

A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause a major nonrecoverable fault (MNRF) Rockwell Automation's ControlLogix 5580, Guard Logix 5580, CompactLogix 5380, and 1756-EN4TR. If exploited, the affected product will become unavailable and require a manual restart to recover it. Additionally, an MNRF could result in a loss of view and/or control of connected devices.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:rockwellautomation:controllogix_5580_firmware:35.011:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:controllogix_5580:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:rockwellautomation:guardlogix_5580_firmware:35.011:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:guardlogix_5580:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:rockwellautomation:compactlogix_5380_firmware:35.011:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:compactlogix_5380:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:rockwellautomation:compact_guardlogix_5380_firmware:35.011:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:compact_guardlogix_5380:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:rockwellautomation:1756-en4tr_firmware:5.001:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:1756-en4tr:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:rockwellautomation:controllogix_5580_process_firmware:35.011:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:controllogix_5580_process:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:rockwellautomation:compactlogix_5380_process_firmware:35.011:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:compactlogix_5380_process:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:rockwellautomation:compactlogix_5480_firmware:35.011:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:compactlogix_5480:-:*:*:*:*:*:*:*

History

04 Mar 2025, 17:11

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:o:rockwellautomation:guardlogix_5580_firmware:35.011:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:guardlogix_5580:-:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:1756-en4tr:-:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:controllogix_5580:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:compactlogix_5480_firmware:35.011:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:1756-en4tr_firmware:5.001:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:compactlogix_5480:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:controllogix_5580_firmware:35.011:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:compact_guardlogix_5380:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:compactlogix_5380_process_firmware:35.011:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:controllogix_5580_process_firmware:35.011:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:compact_guardlogix_5380_firmware:35.011:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:compactlogix_5380_firmware:35.011:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:compactlogix_5380_process:-:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:compactlogix_5380:-:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:controllogix_5580_process:-:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
References () https://www.rockwellautomation.com/en-us/support/advisory.SD1666.html - () https://www.rockwellautomation.com/en-us/support/advisory.SD1666.html - Broken Link
First Time Rockwellautomation compactlogix 5380 Process Firmware
Rockwellautomation controllogix 5580 Firmware
Rockwellautomation
Rockwellautomation 1756-en4tr Firmware
Rockwellautomation compact Guardlogix 5380
Rockwellautomation compactlogix 5380 Process
Rockwellautomation compactlogix 5380 Firmware
Rockwellautomation controllogix 5580 Process
Rockwellautomation compactlogix 5480
Rockwellautomation compactlogix 5480 Firmware
Rockwellautomation compact Guardlogix 5380 Firmware
Rockwellautomation guardlogix 5580
Rockwellautomation guardlogix 5580 Firmware
Rockwellautomation 1756-en4tr
Rockwellautomation compactlogix 5380
Rockwellautomation controllogix 5580 Process Firmware
Rockwellautomation controllogix 5580

16 Apr 2024, 13:24

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-15 22:15

Updated : 2025-03-04 17:43


NVD link : CVE-2024-3493

Mitre link : CVE-2024-3493


JSON object : View

Products Affected

rockwellautomation

  • compactlogix_5380_process
  • compactlogix_5380
  • guardlogix_5580
  • compactlogix_5480_firmware
  • compact_guardlogix_5380
  • 1756-en4tr_firmware
  • compactlogix_5480
  • 1756-en4tr
  • controllogix_5580_process
  • controllogix_5580
  • controllogix_5580_process_firmware
  • compactlogix_5380_process_firmware
  • guardlogix_5580_firmware
  • compactlogix_5380_firmware
  • controllogix_5580_firmware
  • compact_guardlogix_5380_firmware