CVE-2024-5659
MEDIUMDescription
Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result in a major nonrecoverable fault(MNRF/Assert). This vulnerability could be exploited by sending abnormal packets to the mDNS port. If exploited, the availability of the device would be compromised.
Is your site exposed to CVE-2024-5659?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| rockwellautomation | controllogix_5580_firmware |
| rockwellautomation | controllogix_5580 |
| rockwellautomation | guardlogix_5580_firmware |
| rockwellautomation | guardlogix_5580 |
| rockwellautomation | 1756-en4_firmware |
| rockwellautomation | 1756-en4 |
| rockwellautomation | compactlogix_5380_firmware |
| rockwellautomation | compactlogix_5380 |
| rockwellautomation | compact_guardlogix_5380_firmware |
| rockwellautomation | compact_guardlogix_5380 |
| rockwellautomation | compactlogix_5480_firmware |
| rockwellautomation | compactlogix_5480 |
References
Frequently Asked Questions
What is CVE-2024-5659? +
How severe is CVE-2024-5659? +
What products are affected by CVE-2024-5659? +
How do I check if I'm vulnerable to CVE-2024-5659? +
Related Vulnerabilities
In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in the conditional that gates …
MintyItanium Lost-Auction is an auction plugin for Minecraft. Prior to commit 88c920b05042929db334ba06d57f052b42d6b3f8, players can take items like barrier blocks or …
Hyperbridge is a hyper-scalable coprocessor for verifiable, cross-chain interoperability. A critical vulnerability was discovered in the ismp-grandpa crate, that allowed …
The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior …
A logic issue was addressed with improved state management. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS …
Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and …