PatchSiren cyber security CVE debrief
CVE-2024-6089 Rockwell Automation CVE debrief
An input validation vulnerability in Rockwell Automation 5015 - AENFTXT (firmware version 2.011) allows an unauthenticated remote attacker to cause a major nonrecoverable fault on the secondary adapter by sending a manipulated PTP (Precision Time Protocol) packet. Successful exploitation results in a denial-of-service condition requiring a physical power cycle to recover the device. The vulnerability is rated HIGH severity with a CVSS 3.1 score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), indicating network-based attack vector with low complexity, no privileges required, and high availability impact. CISA published this advisory on August 22, 2024 as ICSA-24-235-02.
- Vendor
- Rockwell Automation
- Product
- 5015 - AENFTXT
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-08-22
- Original CVE updated
- 2024-08-22
- Advisory published
- 2024-08-22
- Advisory updated
- 2024-08-22
Who should care
Organizations operating Rockwell Automation 5015 - AENFTXT devices in industrial environments, particularly those relying on PTP for time synchronization. Critical infrastructure operators, manufacturing facilities, and OT security teams should prioritize patching due to the unauthenticated remote exploitability and physical recovery requirement.
Technical summary
The vulnerability exists in the PTP packet processing implementation of the affected firmware. Insufficient input validation allows a malformed PTP packet to trigger a major nonrecoverable fault (MNRF) in the secondary adapter. This is a network-accessible, unauthenticated denial-of-service vulnerability with no confidentiality or integrity impact but complete availability impact on the affected device. Recovery requires physical intervention to power cycle the device.
Defensive priority
HIGH
Recommended defensive actions
- Update affected devices to firmware revision v2.012 or later
- Implement network segmentation to restrict PTP traffic to trusted sources
- Monitor for unexpected device faults or power cycle events
- Apply Rockwell Automation security best practices for industrial control systems
- Use CISA Stakeholder-Specific Vulnerability Categorization (SSVC) for environment-specific prioritization
Evidence notes
CVE published and advisory released 2024-08-22 per CISA CSAF source. Affected product confirmed as Rockwell Automation 5015 - AENFTXT firmware version 2.011. CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H = 7.5. Remediation requires firmware update to v2.012.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-6089 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-6089
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-6089 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-6089
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-235-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-235-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.