{ "id": "CVE-2024-6207", "sourceIdentifier": "PSIRT@rockwellautomation.com", "published": "2024-10-14T21:15:12.460", "lastModified": "2024-10-21T13:20:45.617", "vulnStatus": "Analyzed", "cveTags": [], "descriptions": [ { "lang": "en", "value": "CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html \u00a0and send a specially crafted CIP message to the device. If exploited, a threat actor could help prevent access to the legitimate user and end connections to connected devices including the workstation. To recover the controllers, a download is required which ends any process that the controller is running." }, { "lang": "es", "value": "CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html y enviar un mensaje CIP especialmente manipulado al dispositivo. Si se explota, un actor de amenazas podr\u00eda ayudar a evitar el acceso al usuario leg\u00edtimo y finalizar las conexiones a los dispositivos conectados, incluida la estaci\u00f3n de trabajo. Para recuperar los controladores, se requiere una descarga que finalice cualquier proceso que est\u00e9 ejecutando el controlador." } ], "metrics": { "cvssMetricV40": [ { "source": "PSIRT@rockwellautomation.com", "type": "Secondary", "cvssData": { "version": "4.0", "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X", "baseScore": 8.7, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "NONE", "userInteraction": "NONE", "vulnConfidentialityImpact": "NONE", "vulnIntegrityImpact": "NONE", "vulnAvailabilityImpact": "HIGH", "subConfidentialityImpact": "NONE", "subIntegrityImpact": "NONE", "subAvailabilityImpact": "NONE", "exploitMaturity": "NOT_DEFINED", "confidentialityRequirement": "NOT_DEFINED", "integrityRequirement": "NOT_DEFINED", "availabilityRequirement": "NOT_DEFINED", "modifiedAttackVector": "NOT_DEFINED", "modifiedAttackComplexity": "NOT_DEFINED", "modifiedAttackRequirements": "NOT_DEFINED", "modifiedPrivilegesRequired": "NOT_DEFINED", "modifiedUserInteraction": "NOT_DEFINED", "modifiedVulnConfidentialityImpact": "NOT_DEFINED", "modifiedVulnIntegrityImpact": "NOT_DEFINED", "modifiedVulnAvailabilityImpact": "NOT_DEFINED", "modifiedSubConfidentialityImpact": "NOT_DEFINED", "modifiedSubIntegrityImpact": "NOT_DEFINED", "modifiedSubAvailabilityImpact": "NOT_DEFINED", "Safety": "NOT_DEFINED", "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "valueDensity": "NOT_DEFINED", "vulnerabilityResponseEffort": "NOT_DEFINED", "providerUrgency": "NOT_DEFINED" } } ], "cvssMetricV31": [ { "source": "PSIRT@rockwellautomation.com", "type": "Secondary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" }, "exploitabilityScore": 3.9, "impactScore": 3.6 }, { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" }, "exploitabilityScore": 3.9, "impactScore": 3.6 } ] }, "weaknesses": [ { "source": "PSIRT@rockwellautomation.com", "type": "Secondary", "description": [ { "lang": "en", "value": "CWE-20" } ] }, { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-noinfo" } ] } ], "configurations": [ { "operator": "AND", "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:rockwellautomation:controllogix_5580_firmware:*:*:*:*:*:*:*:*", "versionStartIncluding": "28.011", "versionEndExcluding": "33.017", "matchCriteriaId": "3CCECB24-3DF9-441D-B2E0-7EDD305EA31D" }, { "vulnerable": true, "criteria": "cpe:2.3:o:rockwellautomation:controllogix_5580_firmware:*:*:*:*:*:*:*:*", "versionStartIncluding": "34.011", "versionEndExcluding": "34.014", "matchCriteriaId": "999BE839-8688-4723-A067-788386E528D7" }, { "vulnerable": true, "criteria": "cpe:2.3:o:rockwellautomation:controllogix_5580_firmware:*:*:*:*:*:*:*:*", "versionStartIncluding": "35.011", "versionEndExcluding": "35.013", "matchCriteriaId": "D70BDEA5-B19E-4399-AD46-FA94285B2DEA" } ] }, { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": false, "criteria": "cpe:2.3:h:rockwellautomation:controllogix_5580:-:*:*:*:*:*:*:*", "matchCriteriaId": "51BB883B-B863-4D57-B1C0-FC7B3EBD1EA0" } ] } ] }, { "operator": "AND", "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:rockwellautomation:controllogix_5580_process_firmware:*:*:*:*:*:*:*:*", "versionStartIncluding": "33.011", "versionEndExcluding": "33.017", "matchCriteriaId": "F8EF3D88-B9BC-4FEA-BA35-8657EEE463F2" }, { "vulnerable": true, "criteria": "cpe:2.3:o:rockwellautomation:controllogix_5580_process_firmware:*:*:*:*:*:*:*:*", "versionStartIncluding": "34.011", "versionEndExcluding": "34.014", "matchCriteriaId": "7A3A96A6-242A-4022-8347-E04467DA6FDA" }, { "vulnerable": true, "criteria": "cpe:2.3:o:rockwellautomation:controllogix_5580_process_firmware:*:*:*:*:*:*:*:*", "versionStartIncluding": "35.011", "versionEndExcluding": "35.013", "matchCriteriaId": "7D377807-09D3-4430-8B0D-83BB5514B275" } ] }, { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": false, "criteria": "cpe:2.3:h:rockwellautomation:controllogix_5580_process:-:*:*:*:*:*:*:*", "matchCriteriaId": "AFEDADD8-01DE-4AE5-A0D7-532347FA7DB2" } ] } ] }, { "operator": "AND", "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:rockwellautomation:guardlogix_5580_firmware:*:*:*:*:*:*:*:*", "versionStartIncluding": "31.011", "versionEndExcluding": "33.017", "matchCriteriaId": "BF92BE9B-AF7A-4A04-9438-C30C5ED49B07" }, { "vulnerable": true, "criteria": "cpe:2.3:o:rockwellautomation:guardlogix_5580_firmware:*:*:*:*:*:*:*:*", "versionStartIncluding": "34.011", "versionEndExcluding": "34.014", "matchCriteriaId": "D0E0F65D-98D1-4021-9CB0-402834F46DD8" }, { "vulnerable": true, "criteria": "cpe:2.3:o:rockwellautomation:guardlogix_5580_firmware:*:*:*:*:*:*:*:*", "versionStartIncluding": "35.011", "versionEndExcluding": "35.013", "matchCriteriaId": "956AF3D2-9A47-4BAD-B3A5-37A8965DBB2E" } ] }, { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": false, "criteria": "cpe:2.3:h:rockwellautomation:guardlogix_5580:-:*:*:*:*:*:*:*", "matchCriteriaId": "006B7683-9FDF-4748-BA28-2EA22613E092" } ] } ] }, { "operator": "AND", "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:rockwellautomation:compactlogix_5380_firmware:*:*:*:*:*:*:*:*", "versionStartIncluding": "28.011", "versionEndExcluding": "33.017", "matchCriteriaId": "6C85E19A-8153-4AC2-8A15-DD1CEE9F5B2E" }, { "vulnerable": true, "criteria": "cpe:2.3:o:rockwellautomation:compactlogix_5380_firmware:*:*:*:*:*:*:*:*", "versionStartIncluding": "34.011", "versionEndExcluding": "34.014", "matchCriteriaId": "90519681-C70B-49EE-A551-29D5A9EFCA31" }, { "vulnerable": true, "criteria": "cpe:2.3:o:rockwellautomation:compactlogix_5380_firmware:*:*:*:*:*:*:*:*", "versionStartIncluding": "35.011", "versionEndExcluding": "35.013", "matchCriteriaId": "3A306250-9B1A-49A4-B6C1-E2EFBA49504B" } ] }, { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": false, "criteria": "cpe:2.3:h:rockwellautomation:compactlogix_5380:-:*:*:*:*:*:*:*", "matchCriteriaId": "EDD040ED-B44C-47D0-B4D4-729C378C4F68" } ] } ] }, { "operator": "AND", "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:rockwellautomation:compact_guardlogix_5380_sil_2_firmware:*:*:*:*:*:*:*:*", "versionStartIncluding": "31.011", "versionEndExcluding": "33.017", "matchCriteriaId": "93D9D75D-0C98-408B-9EB1-6315AAE1147B" }, { "vulnerable": true, "criteria": "cpe:2.3:o:rockwellautomation:compact_guardlogix_5380_sil_2_firmware:*:*:*:*:*:*:*:*", "versionStartIncluding": "34.011", "versionEndExcluding": "34.014", "matchCriteriaId": "58CAFC2B-2C95-41E0-BB00-7E7F89103664" }, { "vulnerable": true, "criteria": "cpe:2.3:o:rockwellautomation:compact_guardlogix_5380_sil_2_firmware:*:*:*:*:*:*:*:*", "versionStartIncluding": "35.011", "versionEndExcluding": "35.013", "matchCriteriaId": "37997377-0939-4D3C-8A97-F4F8C6FB1000" } ] }, { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": false, "criteria": "cpe:2.3:h:rockwellautomation:compact_guardlogix_5380_sil_2:-:*:*:*:*:*:*:*", "matchCriteriaId": "E594CDF6-0582-4D5C-B6AA-C8A2E752E29F" } ] } ] }, { "operator": "AND", "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:rockwellautomation:compact_guardlogix_5380_sil_3_firmware:*:*:*:*:*:*:*:*", "versionStartIncluding": "32.013", "versionEndExcluding": "33.017", "matchCriteriaId": "D85D8A23-BC23-41F9-A17A-33239D4C90B5" }, { "vulnerable": true, "criteria": "cpe:2.3:o:rockwellautomation:compact_guardlogix_5380_sil_3_firmware:*:*:*:*:*:*:*:*", "versionStartIncluding": "34.011", "versionEndExcluding": "34.014", "matchCriteriaId": "13C157F1-BD62-4F6A-8DCF-4660983C9948" }, { "vulnerable": true, "criteria": "cpe:2.3:o:rockwellautomation:compact_guardlogix_5380_sil_3_firmware:*:*:*:*:*:*:*:*", "versionStartIncluding": "35.011", "versionEndExcluding": "35.013", "matchCriteriaId": "A01F13C3-42C1-409C-A16E-6BEC723108A2" } ] }, { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": false, "criteria": "cpe:2.3:h:rockwellautomation:compact_guardlogix_5380_sil_3:-:*:*:*:*:*:*:*", "matchCriteriaId": "B82D842C-0930-41AA-83CD-5F235771AE4B" } ] } ] }, { "operator": "AND", "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:rockwellautomation:compactlogix_5480_firmware:*:*:*:*:*:*:*:*", "versionStartIncluding": "32.011", "versionEndExcluding": "33.017", "matchCriteriaId": "A890317E-B6BD-4A0A-B7E0-E50D90506EF1" }, { "vulnerable": true, "criteria": "cpe:2.3:o:rockwellautomation:compactlogix_5480_firmware:*:*:*:*:*:*:*:*", "versionStartIncluding": "34.011", "versionEndExcluding": "34.014", "matchCriteriaId": "881D835B-D7E3-44C5-9B77-CA82EDCE2D3C" }, { "vulnerable": true, "criteria": "cpe:2.3:o:rockwellautomation:compactlogix_5480_firmware:*:*:*:*:*:*:*:*", "versionStartIncluding": "35.011", "versionEndExcluding": "35.013", "matchCriteriaId": "A0ABD910-7EBE-44C8-97E3-2B523CDEE5FA" } ] }, { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": false, "criteria": "cpe:2.3:h:rockwellautomation:compactlogix_5480:-:*:*:*:*:*:*:*", "matchCriteriaId": "80F4F5BE-07DF-402A-BF98-34FBA6A11968" } ] } ] }, { "operator": "AND", "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:rockwellautomation:factorytalk_logix_echo_firmware:*:*:*:*:*:*:*:*", "versionStartIncluding": "33.011", "versionEndExcluding": "34.014", "matchCriteriaId": "02105DF7-661C-47E7-BC52-771356537783" }, { "vulnerable": true, "criteria": "cpe:2.3:o:rockwellautomation:factorytalk_logix_echo_firmware:*:*:*:*:*:*:*:*", "versionStartIncluding": "35.011", "versionEndExcluding": "35.013", "matchCriteriaId": "51ECB73D-C08C-4DE1-BA75-608E9C350751" } ] }, { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": false, "criteria": "cpe:2.3:h:rockwellautomation:factorytalk_logix_echo:-:*:*:*:*:*:*:*", "matchCriteriaId": "7898895B-17A1-499A-9B09-9F6C1C302368" } ] } ] } ], "references": [ { "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1707.html", "source": "PSIRT@rockwellautomation.com", "tags": [ "Vendor Advisory" ] } ] }