Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix
Summary
CISA has issued an alert regarding vulnerabilities in Rockwell Automation's ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, and Compact GuardLogix products. These vulnerabilities, primarily identified as CVE-2021-42260, could lead to a denial of service via crafted data, resulting in major nonrecoverable faults.
IFF Assessment
The identified vulnerabilities can cause denial of service in critical industrial control systems, posing a significant risk to operations.
Severity
Defender Context
This alert highlights critical vulnerabilities in operational technology (OT) systems used in manufacturing. Defenders must prioritize patching or mitigating these issues to prevent potential disruptions to industrial processes. Monitoring for anomalous network traffic that could exploit this 'Infinite Loop' vulnerability is crucial.