ICSA-16-056-01
·
Published 2025-06-05
·
View on CISA ICS-CERT ↗
Rockwell Automation Integrated Architecture Builder Access Violation Memory Error
CVSS 6.3
MEDIUM
CVEs (1)
Remediations
- Rockwell Automation recommends users upgrade to the newest available software versions to mitigate the threat of this vulnerability. They also recommend the following steps: Do not open untrusted project files with IAB.exe. Upgrade Integrated Architecture Builder V9.6.0.7 and earlier to either V9.7.0.2+ or V9.6.0.8+ (available now) using Current Program Updater. Current Program Updater is a program that is installed on the user’s computer when Integrated Architecture Builder is installed. For additional information, please refer to the user guide which is built into the Current Program Updater application. Run all software as “User,” not as an “Administrator,” to minimize the impact of malicious code on the infected system. Use trusted software, software patches, antivirus/antimalware programs and interact only with trusted web sites and attachments. Employ training and awareness programs to educate users on the warning signs of a phishing or social engineering attack. Minimize network exposure for all control system devices and/or systems, and ensure that they are not accessible from the Internet. Locate control system networks and devices behind firewalls, and isolate them from the business network. Use of Microsoft AppLocker or other similar whitelisting applications can help mitigate risk. Information on using AppLocker with Rockwell Automation products is available at (https://rockwellautomation.custhelp.com/app/answers/detail/a_id/546989).
- Rockwell Automation’s security notification is available at the following URL, with a valid account: (https://rockwellautomation.custhelp.com/app/answers/detail/a_id/54102)
- For more information on this vulnerability and more detailed mitigation instructions, please see Rockwell Automation’s public security web page at: (http://www.rockwellautomation.com/security)
Affected Vendors
Rockwell Automation
Affected Products (2)
Rockwell Automation
·
Integrated Architecture Builder
<=9.6.0.7
Rockwell Automation
·
Integrated Architecture Builder
9.7.0.0|9.7.0.1
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more