This content is restricted.
Brief
Summary:
This document is a view of a Common Vulnerabilities and Exposures (CVE) report issued by Rockwell Automation. It highlights three vulnerabilities in the PowerFlex 527 adjustable frequency AC drives, affecting versions v2.001.x and later. The vulnerabilities include:
1. Improper Input Validation (CVE-2024-2425 and CVE-2024-2426) which can cause a denial-of-service, leading to a manual restart.
2. Uncontrolled Resource Consumption (CVE-2024-2427) which can also cause a denial-of-service, leading to a manual restart.
The CVSS v4 scores for these vulnerabilities range from 8.7, indicating a high severity. The report advises users to take risk mitigations and security best practices, such as network segmentation, disabling the web server, and security best practices. Rockwell Automation does not currently have a fix for these vulnerabilities, but users are encouraged to report any suspected malicious activity to CISA.
Highlights content goes here...
This content is restricted.