Description


The connection establishment algorithm found in Rockwell Automation CompactLogix 5370 and ControlLogix 5570 versions 33 and prior does not sufficiently manage its control flow during execution, creating an infinite loop. This may allow an attacker to send specially crafted CIP packet requests to a controller, which may cause denial-of-service conditions in communications with other products.

Weaknesses



CWE-20

134c704f-9b21-4f2e-91b3-4a467353bcc0

Secondary

CWE-20

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L

5.8 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2022-07-27T19:15:08.297Z

3 years ago

Last modified

2025-04-17T14:15:21.730Z

11 months ago