Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multiple actions on certain web pages of the product causing the affected products to become fully unavailable and require a power cycle to recover.
| Software | From | Fixed in |
|---|---|---|
| rockwellautomation / compactlogix_5380_firmware | 33.011 | 33.015 |
| rockwellautomation / compact_guardlogix_5380_firmware | 33.011 | 33.015 |
| rockwellautomation / compactlogix_5480_firmware | 33.011 | 33.015 |
| rockwellautomation / controllogix_5580_firmware | 33.011 | 33.015 |
| rockwellautomation / guardlogix_5580_firmware | 33.011 | 33.015 |
| rockwellautomation / 1756-en4tr_firmware | 3.002 | 3.002.x |