Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-2426— Rockwell Automation - Denial-of-service and Input Validation Vulnerabilities in PowerFlex® 527

CVSS 7.5 · High EPSS 0.21% · P43
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-2426

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Rockwell Automation - Denial-of-service and Input Validation Vulnerabilities in PowerFlex® 527
Source: NVD (National Vulnerability Database)
Vulnerability Description
A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, a disruption in the CIP communication will occur and a manual restart will be required by the user to recover it.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
输入验证不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
Rockwell Automation PowerFlex 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Rockwell Automation PowerFlex 525是美国罗克韦尔(Rockwell Automation)公司的一款可调交流变频器。 Rockwell Automation PowerFlex 527 v2.001.x之前版本存在安全漏洞,该漏洞源于输入验证不正确,导致存在拒绝服务(DOS)漏洞。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Rockwell Automation PowerFlex® 527 v2.001.x < -

II. Public POCs for CVE-2024-2426

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-2426

登录查看更多情报信息。

Same Patch Batch · Rockwell Automation · 2024-03-25 · 3 CVEs total

CVE-2024-24257.5 HIGHRockwell Automation - Denial-of-service and Input Validation Vulnerabilities in PowerFlex®
CVE-2024-24277.5 HIGHRockwell Automation - Denial-of-service and Input Validation Vulnerabilities in PowerFlex®

IV. Related Vulnerabilities

V. Comments for CVE-2024-2426

No comments yet


Leave a comment