← Vulnerability feed

Vulnerability record · CVE-2017-6024 · published 6 May 2017

CVE-2017-6024: Rockwellautomation compactlogix 5380 firmware uncontrolled resource consumption vulnerability

Rockwellautomation · Compactlogix 5380 Firmware

A Resource Exhaustion issue was discovered in Rockwell Automation ControlLogix 5580 controllers V28.011, V28.012, and V28.013; ControlLogix 5580 controllers V29.011; CompactLogix 5380 controllers V28.011; and CompactLogix 5380 controllers V29.011. This vulnerability may allow an attacker to cause a denial of service condition by sending a series of specific CIP-based commands to the controller.

5.9 CVSS 3.1 Medium EPSS 2.6% · top 14.9% CWE-400 · Uncontrolled resource consumption
5.9CVSS 3.1 base score, v2 7.1
2.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A Resource Exhaustion issue was discovered in Rockwell Automation ControlLogix 5580 controllers V28.011, V28.012, and V28.013; ControlLogix 5580 controllers V29.011; CompactLogix 5380 controllers V28.011; and CompactLogix 5380 controllers V29.011. This vulnerability may allow an attacker to cause a denial of service condition by sending a series of specific CIP-based commands to the controller.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securityfocus.com/bid/98309 Third Party AdvisoryVDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-17-094-05 Third Party AdvisoryUS Government Resource
http://www.securityfocus.com/bid/98309 Third Party AdvisoryVDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-17-094-05 Third Party AdvisoryUS Government Resource

Track CVE-2017-6024 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-1161Rockwellautomation compactlogix 1768-l43 firmware inclusion from untrusted sphere vulnerabilityAn attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems…EPSS 5.2%8.7CVE-2024-6207Rockwellautomation controllogix 5580 firmware improper input validation vulnerabilityCVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html  and send a specially crafted CIP messa…EPSS 0.55%8.7CVE-2024-8626Rockwellautomation compactlogix 5380 firmware uncontrolled resource consumption vulnerabilityDue to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vul…EPSS 0.52%8.7CVE-2024-6077Rockwellautomation compactlogix 5380 firmware improper input validation vulnerabilityA denial-of-service vulnerability exists in the Rockwell Automation affected products when specially crafted packets are sent to the CIP Security Obj…EPSS 0.56%8.7CVE-2024-7515Rockwellautomation compactlogix 5380 firmware improper input validation vulnerabilityCVE-2024-7515 IMPACT A denial-of-service vulnerability exists in the affected products. A malformed PTP management packet can cause a major nonrecove…EPSS 0.52%8.7CVE-2024-40619Rockwellautomation controllogix 5580 firmware vulnerabilityCVE-2024-40619 IMPACT A denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a malformed CIP packet is sent…EPSS 0.58%8.7CVE-2024-7507Rockwellautomation compactlogix 5380 firmware improper input validation vulnerabilityCVE-2024-7507 IMPACT A denial-of-service vulnerability exists in the affected products. This vulnerability occurs when a malformed PCCC message is re…EPSS 0.50%8.6CVE-2022-1797Rockwellautomation compactlogix 5380 firmware uncontrolled resource consumption vulnerabilityA malformed Class 3 common industrial protocol message with a cached connection can cause a denial-of-service condition in Rockwell Automation Logix …EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2017-6024), CISA KEV, FIRST EPSS (scores of 2026-10-09). This page is refreshed as NVD updates the record.