Description

A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause a major nonrecoverable fault (MNRF) Rockwell Automation's ControlLogix 5580, Guard Logix 5580, CompactLogix 5380, and 1756-EN4TR. If exploited, the affected product will become unavailable and require a manual restart to recover it. Additionally, an MNRF could result in a loss of view and/or control of connected devices.

Published: 2024-04-15
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Affected Product         First Known in Firmware Revision         Corrected in Firmware Revision         ControlLogix® 5580         V35.011         V35.013, V36.011         GuardLogix 5580         V35.011         V35.013, V36.011         CompactLogix 5380         V35.011         V35.013, V36.011         1756-EN4TR         V5.001         V6.001     Users using the affected software and who are not able to upgrade to one of the corrected versions are encouraged to apply security best practices, where possible.   * Security Best Practices https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight  

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-32079 A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause a major nonrecoverable fault (MNRF) Rockwell Automation's ControlLogix 5580, Guard Logix 5580, CompactLogix 5380, and 1756-EN4TR. If exploited, the affected product will become unavailable and require a manual restart to recover it. Additionally, an MNRF could result in a loss of view and/or control of connected devices.
History

No history.

Subscriptions

Rockwellautomation 1756-en4tr 1756-en4tr Firmware Compact Guardlogix 5380 Compact Guardlogix 5380 Firmware Compactlogix 5380 Compactlogix 5380 Firmware Compactlogix 5380 Process Compactlogix 5380 Process Firmware Compactlogix 5480 Compactlogix 5480 Firmware Controllogix 5580 Controllogix 5580 Firmware Controllogix 5580 Process Controllogix 5580 Process Firmware Guardlogix 5580 Guardlogix 5580 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2024-08-12T15:16:08.155Z

Reserved: 2024-04-08T21:46:38.867Z

Link: CVE-2024-3493

cve-icon Vulnrichment

Updated: 2024-08-01T20:12:07.675Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-15T22:15:09.073

Modified: 2026-06-17T07:44:22.820

Link: CVE-2024-3493

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses