Description
A security issue exists due to improper handling of CIP Class 32’s request when a module is inhibited on the 5094-IF8 device. It causes the module to enter a fault state with the Module LED flashing red. Upon un-inhibiting, the module returns a connection fault (Code 16#0010), and the module cannot recover without a power cycle.
Problem types
CWE-1287: Improper Validation of Specified Type of Input
Product status
Version 2.011 or below
References
www.rockwellautomation.com/...dvisories/advisory.SD1737.html