PatchSiren cyber security CVE debrief
CVE-2024-7567 Rockwell Automation CVE debrief
A denial-of-service vulnerability exists in Rockwell Automation Micro850/870 programmable logic controllers (PLCs) via the CIP/Modbus port. Successful exploitation can disrupt CIP/Modbus communications for a short duration. The vulnerability was disclosed on August 13, 2024, with a CVSS 3.1 score of 5.3 (Medium severity). Affected products are versions prior to v22.011. Rockwell Automation has released firmware version v22.011 to address this issue.
- Vendor
- Rockwell Automation
- Product
- PLC - Micro850/870 (2080 -L50E/2080 -L70E)
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-08-13
- Original CVE updated
- 2024-08-13
- Advisory published
- 2024-08-13
- Advisory updated
- 2024-08-13
Who should care
Organizations operating Rockwell Automation Micro850 or Micro870 PLCs in industrial environments, particularly those with exposed or network-accessible CIP/Modbus ports. Critical infrastructure operators, manufacturing facilities, and OT security teams should prioritize firmware updates to maintain operational continuity.
Technical summary
The vulnerability exists in the CIP/Modbus port implementation of Rockwell Automation Micro850/870 PLCs (2080-L50E/2080-L70E). An attacker can trigger a denial-of-service condition that temporarily disrupts CIP/Modbus communications. The attack vector is network-based with low attack complexity and no required privileges or user interaction. The vulnerability has a CVSS 3.1 score of 5.3 (Medium) with AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L. Remediation is available through firmware update to version v22.011.
Defensive priority
medium
Recommended defensive actions
- Update affected Micro850/870 PLC firmware to version v22.011 or later
- Apply Rockwell Automation security best practices for industrial control systems
- Implement network segmentation to limit exposure of CIP/Modbus ports
- Monitor CIP/Modbus communications for unexpected disruptions
- Review and implement CISA ICS recommended practices for defense-in-depth
Evidence notes
The vulnerability affects Rockwell Automation PLC - Micro850/870 (2080-L50E/2080-L70E) with firmware versions prior to v22.011. The issue is a network-accessible denial-of-service condition affecting industrial control system communications. CISA published advisory ICSA-24-226-07 on August 13, 2024, coordinating disclosure.
Official resources
-
CVE-2024-7567 CVE record
CVE.org
-
CVE-2024-7567 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
2024-08-13