
Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix és GuardLogix
SZERZŐ
CISA
FORRÁS
All CISA Advisories
DATE
READ
2 perc olvasás
A Rockwell Automation az alábbi CompactLogix és ControlLogix szabályzókon található kritikus hibákat azonosította, különösen azoknál, amelyek V35.015 verzióig vagy a 1.072-es verziótól alacsonyabb firmware-t futtatnak. …
CSAF Summary: Exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition. Affected Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix versions are: CompactLogix 5370 <=V35.015, Compact GuardLogix 5370: <=V35.015, Rockwell Automation ControlLogix 5570: <=V35.015, Rockwell Automation GuardLogix 5570: <=V35.015, Rockwell Automation CompactLogix 5380: <=V34.012, Rockwell Automation CompactLogix 5380: <=V35.011, Rockwell Automation Compact GuardLogix 5380: <=V34.012, Rockwell Automation Compact GuardLogix 5380: <=V35.011, Rockwell Automation CompactLogix 5480: <=V34.012, Rockwell Automation CompactLogix 5480: <=V35.011, Rockwell Automation ControlLogix 5580: <=V34.012, Rockwell Automation ControlLogix 5580: <=V35.011, Rockwell Automation GuardLogix 5580: <=V34.012, Rockwell Automation GuardLogix 5580: <=V35.011, Rockwell Automation CompactLogix 5380 Recovery Image: <=1.072, Rockwell Automation Compact GuardLogix 5380 Recovery Image: <=1.072, Rockwell Automation CompactLogix 5480 Recovery Image: <=1.072, Rockwell Automation ControlLogix 5580 Recovery Image: <=1.072, Rockwell Automation GuardLogix 5580 Recovery Image: <=1.072. Remediation: Update to the following CompactLogix 5370: V35.016, V36.011 and later, Compact GuardLogix 5370: V35.016, V36.011 and later, ControlLogix 5570: V35.016, V36.011 and later, GuardLogix 5570: V35.016, V36.011 and later, CompactLogix 5380: V34.014, V35.013, V36.011 and later, Compact GuardLogix 5380: V34.014, V35.013, V36.011 and later, CompactLogix 5480: V34.014, V35.013, V36.011 and later, ControlLogix 5580: V34.014, V35.013, V36.011 and later, GuardLogix 5580: V34.014, V35.013, V36.011 and later, CompactLogix 5380 Recovery Image: Update to boot firmware 1.072 or greater. If using V36.013, V37.011 or later, already has corrected boot firmware is installed, Compact GuardLogix 5380 Recovery Image: Update to boot firmware 1.072 or greater. If using V36.013, V37.011 or later, already has corrected boot firmware is installed, CompactLogix 5480 Recovery Image: Update to boot firmware 1.072 or greater. If using V36.013, V37.011 or later, already has corrected boot firmware is installed, ControlLogix 5580 Recovery Image: Update to boot firmware 1.072 or greater. If using V36.013, V37.011 or later, already has corrected boot firmware is installed, GuardLogix 5580 Recovery Image: Update to boot firmware 1.072 or greater. If using V36.013, V37.011 or later, already has corrected boot firmware is installed. Affected CWE: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’). Relevant CVSS: 3.1, Base Score: 8.6, Severity: HIGH, CVSS: 3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H, 4.0, 9.2, CRITICAL, CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H. Legal Notice and Terms of Use.