Today > vulnerabilities   -   You can now download lists of IOCs here!

CVE-2024-6089

July 16, 2024, 6 p.m.

Product(s) Impacted

Rockwell Automation 5015 - AENFTXT

Description

An input validation vulnerability exists in the Rockwell Automation 5015 - AENFTXT when a manipulated PTP packet is sent, causing the secondary adapter to result in a major nonrecoverable fault. If exploited, a power cycle is required to recover the product.

Weaknesses

CWE-20
Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE ID: 20

Date

Published: July 16, 2024, 5:15 p.m.

Last Modified: July 16, 2024, 6 p.m.

Status : Undergoing Analysis

CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.

More info

Source

PSIRT@rockwellautomation.com

References

https://www.rockwellautomation.com/ PSIRT@rockwellautomation.com