CVE-2024-7515
Estado: AnalizadaAlta (8.7)—
CVE-2024-7515 IMPACT
A denial-of-service vulnerability exists in the affected products. A malformed PTP management packet can cause a major nonrecoverable fault in the controller.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 8.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.52%
- Percentil entre todas las CVEs puntuadas: 42
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (6)
Rockwellautomation — Compact Guardlogix 5380 SIL 2 FirmwareRockwellautomation — Compact Guardlogix 5380 SIL 3 FirmwareRockwellautomation — Compactlogix 5380 FirmwareRockwellautomation — Compactlogix 5480 FirmwareRockwellautomation — Controllogix 5580 FirmwareRockwellautomation — Guardlogix 5580 Firmware
CWE
- CWE-20
- NVD-CWE-noinfo
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-7515",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-7515",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-08-14T19:54:17.968076Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "PSIRT@rockwellautomation.com",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 8.7,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "PSIRT@rockwellautomation.com",
"affectedData": [
{
"vendor": "Rockwell Automation",
"product": "CompactLogix 5380 (5069-L3z)",
"versions": [
{
"status": "affected",
"version": "28.011"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Rockwell Automation",
"product": "ControlLogix® 5580 (1756- L8z)",
"versions": [
{
"status": "affected",
"version": "28.011"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Rockwell Automation",
"product": "GuardLogix 5580 (1756- L8zS)",
"versions": [
{
"status": "affected",
"version": "28.011"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Rockwell Automation",
"product": "Compact GuardLogix 5380 (5069 – L3zS2)",
"versions": [
{
"status": "affected",
"version": "28.011"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Rockwell Automation",
"product": "CompactLogix 5480 (5069-L4)",
"versions": [
{
"status": "affected",
"version": "28.011"
}
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:o:rockwellautomation:compactlogix_5380_firmware:v28.011:*:*:*:*:*:*:*"
],
"vendor": "rockwellautomation",
"product": "compactlogix_5380_firmware",
"versions": [
{
"status": "affected",
"version": "v28.011"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:rockwellautomation:controllogix_5580_firmware:v28.011:*:*:*:*:*:*:*"
],
"vendor": "rockwellautomation",
"product": "controllogix_5580_firmware",
"versions": [
{
"status": "affected",
"version": "v28.011"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:rockwellautomation:guardlogix_5580_firmware:28.011:*:*:*:*:*:*:*"
],
"vendor": "rockwellautomation",
"product": "guardlogix_5580_firmware",
"versions": [
{
"status": "affected",
"version": "28.011"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:rockwellautomation:compact_guardlogix_5380_firmware:28.011:*:*:*:*:*:*:*"
],
"vendor": "rockwellautomation",
"product": "compact_guardlogix_5380_firmware",
"versions": [
{
"status": "affected",
"version": "28.011"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:rockwellautomation:compactlogix_5480_firmware:28.011:*:*:*:*:*:*:*"
],
"vendor": "rockwellautomation",
"product": "compactlogix_5480_firmware",
"versions": [
{
"status": "affected",
"version": "28.011"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-08-14T20:15:13.150",
"references": [
{
"url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD%201686.html",
"tags": [
"Vendor Advisory"
],
"source": "PSIRT@rockwellautomation.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "PSIRT@rockwellautomation.com",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "CVE-2024-7515 IMPACT\n\nA denial-of-service vulnerability exists in the affected products. A malformed PTP management packet can cause a major nonrecoverable fault in the controller."
},
{
"lang": "es",
"value": "CVE-2024-7515 IMPACT Existe una vulnerabilidad de denegación de servicio en los productos afectados. Un paquete de administración PTP con formato incorrecto puede causar un fallo importante no recuperable en el controlador."
}
],
"lastModified": "2026-06-17T08:20:21.240",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:rockwellautomation:compactlogix_5380_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AABBF4EF-9F0E-432D-A535-F74402CFD05D",
"versionEndExcluding": "34.014",
"versionStartIncluding": "28.011"
},
{
"criteria": "cpe:2.3:o:rockwellautomation:compactlogix_5380_firmware:35.011:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "305CDBFF-404A-45F5-A391-1B18F446D1B8"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:rockwellautomation:compactlogix_5380:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "EDD040ED-B44C-47D0-B4D4-729C378C4F68"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:rockwellautomation:controllogix_5580_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E5B18F7F-80AB-4146-9D65-B1DB4C2FAA8D",
"versionEndExcluding": "34.014",
"versionStartIncluding": "28.011"
},
{
"criteria": "cpe:2.3:o:rockwellautomation:controllogix_5580_firmware:35.011:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A29D3775-CAB3-45CF-96CE-71D0672C7E37"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:rockwellautomation:controllogix_5580:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "51BB883B-B863-4D57-B1C0-FC7B3EBD1EA0"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:rockwellautomation:guardlogix_5580_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CC2E9A2F-AFC7-442D-88FC-C3217ABB560E",
"versionEndExcluding": "34.014",
"versionStartIncluding": "31.011"
},
{
"criteria": "cpe:2.3:o:rockwellautomation:guardlogix_5580_firmware:35.011:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "64CAC9B1-19E5-44BB-B814-DDA98B7290E4"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:rockwellautomation:guardlogix_5580:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "006B7683-9FDF-4748-BA28-2EA22613E092"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:rockwellautomation:compact_guardlogix_5380_sil_2_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "560A9F50-DBCF-48CF-856B-BE061C490697",
"versionEndExcluding": "34.014",
"versionStartIncluding": "31.011"
},
{
"criteria": "cpe:2.3:o:rockwellautomation:compact_guardlogix_5380_sil_2_firmware:35.011:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F7A5DA9B-E1CA-45FF-8A9B-60B1E506F981"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:rockwellautomation:compact_guardlogix_5380_sil_2:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E594CDF6-0582-4D5C-B6AA-C8A2E752E29F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:rockwellautomation:compact_guardlogix_5380_sil_3_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3631A2E0-00BA-4DF2-94C2-6906B9A3E941",
"versionEndExcluding": "34.014",
"versionStartIncluding": "32.013"
},
{
"criteria": "cpe:2.3:o:rockwellautomation:compact_guardlogix_5380_sil_3_firmware:35.011:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ABE90277-EB8A-4ECE-A573-C1814F35CB47"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:rockwellautomation:compact_guardlogix_5380_sil_3:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B82D842C-0930-41AA-83CD-5F235771AE4B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:rockwellautomation:compactlogix_5480_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8C025589-66EE-40EF-8CE6-9A7B76D74BF4",
"versionEndExcluding": "34.014",
"versionStartIncluding": "32.011"
},
{
"criteria": "cpe:2.3:o:rockwellautomation:compactlogix_5480_firmware:35.011:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "61F8EA3B-C51C-4CB1-9BB3-017577DC6684"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:rockwellautomation:compactlogix_5480:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "80F4F5BE-07DF-402A-BF98-34FBA6A11968"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "PSIRT@rockwellautomation.com"
}