Brief

Summary:

This document is a view of a Common Vulnerabilities and Exposures (CVE) report issued by Rockwell Automation. It highlights three vulnerabilities in the PowerFlex 527 adjustable frequency AC drives, affecting versions v2.001.x and later. The vulnerabilities include:

1. Improper Input Validation (CVE-2024-2425 and CVE-2024-2426) which can cause a denial-of-service, leading to a manual restart.
2. Uncontrolled Resource Consumption (CVE-2024-2427) which can also cause a denial-of-service, leading to a manual restart.

The CVSS v4 scores for these vulnerabilities range from 8.7, indicating a high severity. The report advises users to take risk mitigations and security best practices, such as network segmentation, disabling the web server, and security best practices. Rockwell Automation does not currently have a fix for these vulnerabilities, but users are encouraged to report any suspected malicious activity to CISA.

View CSAF 1. EXECUTIVE SUMMARY CVSS v4 8.7 ATTENTION: Exploitable remotely/low attack complexity Vendor: Rockwell Automation Equipment: PowerFlex 527 Vulnerabilities: Improper Input Validation, Uncontrolled Resource Consumption 2. RISK EVALUATION Successful exploitation of this these vulnerabilities could crash the device and require a manual restart to recover. 3. TECHNICAL DETAILS 3.1 AFFECTED PRODUCTS Rockwell Automation reports

This content is restricted.

Highlights content goes here...

View CSAF 1. EXECUTIVE SUMMARY CVSS v4 8.7 ATTENTION: Exploitable remotely/low attack complexity Vendor: Rockwell Automation Equipment: PowerFlex 527 Vulnerabilities: Improper Input Validation, Uncontrolled Resource Consumption 2. RISK EVALUATION Successful exploitation of this these vulnerabilities could crash the device and require a manual restart to recover. 3. TECHNICAL DETAILS 3.1 AFFECTED PRODUCTS Rockwell Automation reports

This content is restricted.

Cybersecurity and Infrastructure Security Agency

Quick Insight
RADA.AI
RADA.AI
Hello! I'm RADA.AI - Regulatory Analysis and Decision Assistance. Your Intelligent guide for compliance and decision-making. How can i assist you today?
Suggested

Form successfully submitted. One of our GRI rep will contact you shortly

Thanking You!

Enter your Email

Enter your registered username/email id.

Enter your Email

Enter your email id below to signup.
Individual Plan
$125 / month OR $1250 / year
Features
Best for: Researchers, Legal professionals, Academics
Enterprise Plan
Contact for Pricing
Features
Best for: Law Firms, Corporations, Government Bodies