Buffer overflow in Rockwell Automation products - CVE-2024-12373
Published: January 8, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error. A remote attacker can trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
PowerMonitor 1000 PM1k 1408-BC3A-ENT
PowerMonitor 1000 PM1k 1408-TS3A-485
PowerMonitor 1000 PM1k 1408-TS3A-ENT
PowerMonitor 1000 PM1k 1408-EM3A-485
PowerMonitor 1000 PM1k 1408-EM3A-ENT
PowerMonitor 1000 PM1k 1408-TR1A-485
PowerMonitor 1000 PM1k 1408-TR2A-485
PowerMonitor 1000 PM1k 1408-EM1A-485
PowerMonitor 1000 PM1k 1408-EM2A-485
PowerMonitor 1000 PM1k 1408-TR1A-ENT
PowerMonitor 1000 PM1k 1408-TR2A-ENT
PowerMonitor 1000 PM1k 1408-EM1A-ENT
PowerMonitor 1000 PM1k 1408-EM2A-ENT
How to mitigate CVE-2024-12373
PowerMonitor 1000 PM1k 1408-BC3A-ENT - update to 4.020
PowerMonitor 1000 PM1k 1408-TS3A-485 - update to 4.020
PowerMonitor 1000 PM1k 1408-TS3A-ENT - update to 4.020
PowerMonitor 1000 PM1k 1408-EM3A-485 - update to 4.020
PowerMonitor 1000 PM1k 1408-EM3A-ENT - update to 4.020
PowerMonitor 1000 PM1k 1408-TR1A-485 - update to 4.020
PowerMonitor 1000 PM1k 1408-TR2A-485 - update to 4.020
PowerMonitor 1000 PM1k 1408-EM1A-485 - update to 4.020
PowerMonitor 1000 PM1k 1408-EM2A-485 - update to 4.020
PowerMonitor 1000 PM1k 1408-TR1A-ENT - update to 4.020
PowerMonitor 1000 PM1k 1408-TR2A-ENT - update to 4.020
PowerMonitor 1000 PM1k 1408-EM1A-ENT - update to 4.020
PowerMonitor 1000 PM1k 1408-EM2A-ENT - update to 4.020