CVE-2020-6998

The connection establishment algorithm found in Rockwell Automation CompactLogix 5370 and ControlLogix 5570 versions 33 and prior does not sufficiently manage its control flow during execution, creating an infinite loop. This may allow an attacker to send specially crafted CIP packet requests to a controller, which may cause denial-of-service conditions in communications with other products.
References
Link Resource
https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1130398 Permissions Required Vendor Advisory
https://www.cisa.gov/uscert/ics/advisories/icsa-21-061-02 Third Party Advisory US Government Resource
https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1130398 Permissions Required Vendor Advisory
https://www.cisa.gov/uscert/ics/advisories/icsa-21-061-02 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:rockwellautomation:armor_compact_guardlogix_5370_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:armor_compact_guardlogix_5370:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:rockwellautomation:compact_guardlogix_5370_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:compact_guardlogix_5370:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:rockwellautomation:compactlogix_5370_l1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:compactlogix_5370_l1:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:rockwellautomation:compactlogix_5370_l2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:compactlogix_5370_l2:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:rockwellautomation:compactlogix_5370_l3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:compactlogix_5370_l3:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:rockwellautomation:controllogix_5570_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:controllogix_5570:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:rockwellautomation:guardlogix_5560_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:guardlogix_5560:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:rockwellautomation:guardlogix_5570_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:guardlogix_5570:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:rockwellautomation:guardlogix_5580_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:guardlogix_5580:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:36

Type Values Removed Values Added
References () https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1130398 - Permissions Required, Vendor Advisory () https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1130398 - Permissions Required, Vendor Advisory
References () https://www.cisa.gov/uscert/ics/advisories/icsa-21-061-02 - Third Party Advisory, US Government Resource () https://www.cisa.gov/uscert/ics/advisories/icsa-21-061-02 - Third Party Advisory, US Government Resource
CVSS v2 : unknown
v3 : 8.6
v2 : unknown
v3 : 5.8

04 Aug 2022, 02:39

Type Values Removed Values Added
CPE cpe:2.3:o:rockwellautomation:guardlogix_5570_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:armor_compact_guardlogix_5370_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:controllogix_5570:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:compactlogix_5370_l1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:armor_compact_guardlogix_5370:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:guardlogix_5560_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:guardlogix_5560:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:compactlogix_5370_l3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:guardlogix_5570:-:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:compactlogix_5370_l1:-:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:compactlogix_5370_l2:-:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:compactlogix_5370_l3:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:compact_guardlogix_5370_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:compact_guardlogix_5370:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:compactlogix_5370_l2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:controllogix_5570_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:guardlogix_5580:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:guardlogix_5580_firmware:*:*:*:*:*:*:*:*
CWE CWE-20
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.6
References (CONFIRM) https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1130398 - (CONFIRM) https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1130398 - Permissions Required, Vendor Advisory
References (CONFIRM) https://www.cisa.gov/uscert/ics/advisories/icsa-21-061-02 - (CONFIRM) https://www.cisa.gov/uscert/ics/advisories/icsa-21-061-02 - Third Party Advisory, US Government Resource

27 Jul 2022, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-07-27 21:15

Updated : 2024-11-21 05:36


NVD link : CVE-2020-6998

Mitre link : CVE-2020-6998

CVE.ORG link : CVE-2020-6998


JSON object : View

Products Affected

rockwellautomation

  • controllogix_5570_firmware
  • compactlogix_5370_l2_firmware
  • guardlogix_5560
  • guardlogix_5570_firmware
  • compact_guardlogix_5370_firmware
  • guardlogix_5580_firmware
  • compactlogix_5370_l1_firmware
  • compact_guardlogix_5370
  • compactlogix_5370_l3_firmware
  • controllogix_5570
  • guardlogix_5580
  • compactlogix_5370_l2
  • guardlogix_5570
  • armor_compact_guardlogix_5370_firmware
  • compactlogix_5370_l1
  • compactlogix_5370_l3
  • guardlogix_5560_firmware
  • armor_compact_guardlogix_5370
CWE
CWE-20

Improper Input Validation