CVE-2024-6098

EUVD-2024-47249
When performing an online tag generation to devices which communicate 
using the ControlLogix protocol, a machine-in-the-middle, or a device 
that is not configured correctly, could deliver a response leading to 
unrestricted or unregulated resource allocation. This could cause a 
denial-of-service condition and crash the Kepware application. By 
default, these functions are turned off, yet they remain accessible for 
users who recognize and require their advantages.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
ADJACENT_NETWORK
HIGH
NONE
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
icscertCNA
5.3 MEDIUM
ADJACENT_NETWORK
HIGH
NONE
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H