CVE-2024-5659: Rockwellautomation 1756-EN4 Firmware
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result in a major nonrecoverable fault(MNRF/Assert). This vulnerability could be exploited by sending abnormal packets to the mDNS port. If exploited, the availability of the device would be compromised.
Affected products
- Rockwellautomation 1756-EN4 Firmware: version 4.001 only
- Rockwellautomation Compact Guardlogix 5380 Firmware: version 34.011 only
- Rockwellautomation Compactlogix 5380 Firmware: version 34.011 only
- Rockwellautomation Compactlogix 5480 Firmware: version 34.011 only
- Rockwellautomation Controllogix 5580 Firmware: version 34.011 only
- Rockwellautomation Guardlogix 5580 Firmware: version 34.011 only
Published 2024-06-14. Last modified 2026-06-17.