Severity
Medium
Analysis Summary
A remote, unauthenticated threat actor can repeatedly send specific CIP packets to an affected PowerFlex 525 drive, which may allow disruption of the availability of the device.
Impact
- Resource exhaustion
- Denial of service
- Memory corruption
Affected Vendors
Rockwell Automation
Affected Products
PowerFlex 525 AC Drives
Remediation
Vendor has released the patch/ firmware to address this vulnerability. Download the latest version of the firmware from:
https://compatibility.rockwellautomation.com/Pages/MultiProductDownload.aspx?Keyword=25B&crumb=112