CVE-2024-3493

A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause a major nonrecoverable fault (MNRF) Rockwell Automation's ControlLogix 5580, Guard Logix5580,CompactLogix 5380,and 1756-EN4TR. If exploited, the affected product will become unavailable and require a manual restart to recover it. Additionally, an MNRF could result in a loss of view and/or control of connected devices. 

ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
RockwellCNA
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 7%
VendorProductVersion
rockwellautomationcontrollogix_5580_firmware
35.011
rockwellautomationguardlogix_5580_firmware
35.011
rockwellautomationcompactlogix_5380_firmware
35.011
rockwellautomationcompact_guardlogix_5380_firmware
35.011
rockwellautomation1756-en4tr_firmware
5.001
rockwellautomationcontrollogix_5580_process_firmware
35.011
rockwellautomationcompactlogix_5380_process_firmware
35.011
rockwellautomationcompactlogix_5480_firmware
35.011
𝑥
= Vulnerable software versions