CVE-2017-9312 describes a denial-of-service vulnerability in Allen-Bradley L30ERMS safety devices (v30 and earlier) due to improper handling of TCP option fields, causing immediate device reboots upon receiving a crafted TCP packet. This high-severity vulnerability (CVSS 7.5) is network-exploitable with low attack complexity and no user interaction required, leading to a complete loss of availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 30CPE matchmatch criteria | cpe:2.3:o:rockwellautomation:allen-bradley_l30erms_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.