VYPR
Unrated severityNVD Advisory· Published Jun 25, 2018· Updated Sep 16, 2024

CVE-2017-9312

CVE-2017-9312

Description

Improperly implemented option-field processing in the TCP/IP stack on Allen-Bradley L30ERMS safety devices v30 and earlier causes a denial of service. When a crafted TCP packet is received, the device reboots immediately.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Improper TCP packet processing in Allen-Bradley CompactLogix and GuardLogix controllers before v30.014 causes denial of service via crafted packet.

Vulnerability

The vulnerability resides in the TCP/IP stack of Allen-Bradley CompactLogix and GuardLogix 5370 controllers (including L30ERMS devices) running version 30.014 and prior [1]. Improper input validation in option-field processing allows a single crafted TCP packet to trigger an immediate reboot.

Exploitation

An attacker can exploit this remotely without authentication or user interaction [1]. The attacker only needs to send a specially crafted TCP packet to the device's network interface. The vulnerability is rated as low skill level to exploit [1].

Impact

Successful exploitation causes the controller to enter a Major Non-Recoverable Fault (MNRF) state, resulting in a denial-of-service condition [1]. While the controller goes into a safe state, recovery requires the user to download the application program again [1].

Mitigation

Rockwell Automation recommends upgrading to the latest firmware version (post-30.014) to remediate the issue [1]. As of the advisory, no specific workarounds are available, but the controller's fail-safe behavior mitigates physical damage [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.