CVE-2024-8626

Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multiple actions on certain web pages of the product causing the affected products to become fully unavailable and require a power cycle to recover.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:rockwellautomation:compactlogix_5380_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:compactlogix_5380:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:rockwellautomation:compact_guardlogix_5380_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:compact_guardlogix_5380:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:rockwellautomation:compactlogix_5480_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:compactlogix_5480:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:rockwellautomation:controllogix_5580_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:controllogix_5580:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:rockwellautomation:guardlogix_5580_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:guardlogix_5580:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:rockwellautomation:1756-en4tr_firmware:3.002:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:1756-en4tr:-:*:*:*:*:*:*:*

History

17 Jun 2026, 08:23

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-401
First Time Rockwellautomation compactlogix 5380
Rockwellautomation controllogix 5580 Firmware
Rockwellautomation compact Guardlogix 5380 Firmware
Rockwellautomation compactlogix 5480
Rockwellautomation compactlogix 5380 Firmware
Rockwellautomation 1756-en4tr Firmware
Rockwellautomation guardlogix 5580
Rockwellautomation 1756-en4tr
Rockwellautomation
Rockwellautomation compact Guardlogix 5380
Rockwellautomation compactlogix 5480 Firmware
Rockwellautomation guardlogix 5580 Firmware
Rockwellautomation controllogix 5580
References () https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1706.html - () https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1706.html - Vendor Advisory
CPE cpe:2.3:o:rockwellautomation:compact_guardlogix_5380_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:1756-en4tr:-:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:controllogix_5580:-:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:compactlogix_5380:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:controllogix_5580_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:1756-en4tr_firmware:3.002:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:guardlogix_5580_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:guardlogix_5580:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:compactlogix_5380_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:compactlogix_5480_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:compact_guardlogix_5380:-:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:compactlogix_5480:-:*:*:*:*:*:*:*

10 Oct 2024, 12:56

Type Values Removed Values Added
Summary
  • (es) Debido a una fuga de memoria, existe una vulnerabilidad de denegación de servicio en los productos afectados de Rockwell Automation. Un agente malintencionado podría aprovechar esta vulnerabilidad realizando múltiples acciones en determinadas páginas web del producto, lo que provocaría que los productos afectados dejaran de estar disponibles por completo y fuera necesario apagar y encender para recuperarse.

08 Oct 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-08 17:15

Updated : 2026-06-17 08:23


NVD link : CVE-2024-8626

Mitre link : CVE-2024-8626

CVE.ORG link : CVE-2024-8626


JSON object : View

Products Affected

rockwellautomation

  • compactlogix_5480
  • compact_guardlogix_5380_firmware
  • guardlogix_5580_firmware
  • guardlogix_5580
  • compact_guardlogix_5380
  • 1756-en4tr_firmware
  • 1756-en4tr
  • controllogix_5580
  • compactlogix_5380
  • controllogix_5580_firmware
  • compactlogix_5480_firmware
  • compactlogix_5380_firmware
CWE
CWE-400

Uncontrolled Resource Consumption

CWE-401

Missing Release of Memory after Effective Lifetime