PatchSiren cyber security CVE debrief
CVE-2024-45825 Rockwell Automation CVE debrief
A denial-of-service vulnerability exists in Rockwell Automation 5015-U8IHFT devices running firmware version 1.012 and prior. The vulnerability can be triggered when a malformed Common Industrial Protocol (CIP) packet is sent over the network to the affected device, resulting in a major nonrecoverable fault that causes denial-of-service. This vulnerability has a CVSS 3.1 score of 7.5 (HIGH severity) with a vector of AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating network-based attack vector with low attack complexity, no privileges required, and no user interaction needed. The vulnerability was published on September 12, 2024. Rockwell Automation has released firmware version 2.011 to address this issue.
- Vendor
- Rockwell Automation
- Product
- 5015-U8IHFT
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-09-12
- Original CVE updated
- 2024-09-12
- Advisory published
- 2024-09-12
- Advisory updated
- 2024-09-12
Who should care
Organizations operating Rockwell Automation 5015-U8IHFT devices in industrial environments, particularly those with network-exposed CIP endpoints. Critical infrastructure operators, manufacturing facilities, and OT security teams should prioritize patching due to the unauthenticated, remotely exploitable nature of this denial-of-service vulnerability.
Technical summary
The vulnerability exists in the CIP protocol implementation of Rockwell Automation 5015-U8IHFT devices. A malformed CIP packet sent over the network triggers a major nonrecoverable fault, causing complete device failure and denial-of-service. The attack requires no authentication or user interaction and can be executed remotely over the network. The CVSS 3.1 score of 7.5 reflects high availability impact with network accessibility and low attack complexity. Firmware version 2.011 contains the vendor fix for this vulnerability.
Defensive priority
HIGH
Recommended defensive actions
- Update affected Rockwell Automation 5015-U8IHFT devices to firmware version 2.011 or later.
- If immediate patching is not feasible, implement network segmentation to restrict CIP traffic to authorized sources only.
- Apply CISA ICS recommended security best practices for industrial control systems.
- Monitor network traffic for anomalous CIP packets directed at affected devices.
- Review Rockwell Automation security advisory for additional vendor-specific guidance.
Evidence notes
Vulnerability details sourced from CISA ICS Advisory ICSA-24-256-21. Affected product confirmed as Rockwell Automation 5015-U8IHFT firmware version 1.012 and prior. CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H confirms network-accessible, unauthenticated denial-of-service condition. Remediation path confirmed through vendor fix to version 2.011.
Official resources
-
CVE-2024-45825 CVE record
CVE.org
-
CVE-2024-45825 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
2024-09-12