CVE-2024-8626: Rockwellautomation 1756-EN4TR Firmware
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multiple actions on certain web pages of the product causing the affected products to become fully unavailable and require a power cycle to recover.
Affected products
- Rockwellautomation 1756-EN4TR Firmware: version 3.002 only
- Rockwellautomation Compact Guardlogix 5380 Firmware: from 33.011, before 33.015 (fixed in 33.015)
- Rockwellautomation Compactlogix 5380 Firmware: from 33.011, before 33.015 (fixed in 33.015)
- Rockwellautomation Compactlogix 5480 Firmware: from 33.011, before 33.015 (fixed in 33.015)
- Rockwellautomation Controllogix 5580 Firmware: from 33.011, before 33.015 (fixed in 33.015)
- Rockwellautomation Guardlogix 5580 Firmware: from 33.011, before 33.015 (fixed in 33.015)
Published 2024-10-08. Last modified 2026-06-17.