PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-45825 Rockwell Automation CVE debrief

A denial-of-service vulnerability exists in Rockwell Automation 5015-U8IHFT devices running firmware version 1.012 and prior. The vulnerability can be triggered when a malformed Common Industrial Protocol (CIP) packet is sent over the network to the affected device, resulting in a major nonrecoverable fault that causes denial-of-service. This vulnerability has a CVSS 3.1 score of 7.5 (HIGH severity) with a vector of AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating network-based attack vector with low attack complexity, no privileges required, and no user interaction needed. The vulnerability was published on September 12, 2024. Rockwell Automation has released firmware version 2.011 to address this issue.

Vendor
Rockwell Automation
Product
5015-U8IHFT
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-09-12
Original CVE updated
2024-09-12
Advisory published
2024-09-12
Advisory updated
2024-09-12

Who should care

Organizations operating Rockwell Automation 5015-U8IHFT devices in industrial environments, particularly those with network-exposed CIP endpoints. Critical infrastructure operators, manufacturing facilities, and OT security teams should prioritize patching due to the unauthenticated, remotely exploitable nature of this denial-of-service vulnerability.

Technical summary

The vulnerability exists in the CIP protocol implementation of Rockwell Automation 5015-U8IHFT devices. A malformed CIP packet sent over the network triggers a major nonrecoverable fault, causing complete device failure and denial-of-service. The attack requires no authentication or user interaction and can be executed remotely over the network. The CVSS 3.1 score of 7.5 reflects high availability impact with network accessibility and low attack complexity. Firmware version 2.011 contains the vendor fix for this vulnerability.

Defensive priority

HIGH

Recommended defensive actions

  • Update affected Rockwell Automation 5015-U8IHFT devices to firmware version 2.011 or later.
  • If immediate patching is not feasible, implement network segmentation to restrict CIP traffic to authorized sources only.
  • Apply CISA ICS recommended security best practices for industrial control systems.
  • Monitor network traffic for anomalous CIP packets directed at affected devices.
  • Review Rockwell Automation security advisory for additional vendor-specific guidance.

Evidence notes

Vulnerability details sourced from CISA ICS Advisory ICSA-24-256-21. Affected product confirmed as Rockwell Automation 5015-U8IHFT firmware version 1.012 and prior. CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H confirms network-accessible, unauthenticated denial-of-service condition. Remediation path confirmed through vendor fix to version 2.011.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-45825 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-45825

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-45825 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-45825

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-256-21.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-256-21

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.