CVE-2024-6089 HIGH

CVE-2024-6089: Rockwell Automation Major nonrecoverable fault in 5015 – AENFTXT

Vendor Rockwell Automation
Product 5015 - AENFTXT
Weakness CWE-20 · Input validation
Published July 16, 2024
Last update August 1, 2024

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

An input validation vulnerability exists in the Rockwell Automation 5015 - AENFTXT when a manipulated PTP packet is sent, causing the secondary adapter to result in a major nonrecoverable fault. If exploited, a power cycle is required to recover the product.

Key dates

02Disclosure timeline

July 16, 2024 CVE published
August 1, 2024 Record updated