ICSA-21-133-01
·
Published 2021-05-13
·
View on CISA ICS-CERT ↗
Rockwell Automation Connected Components Workbench
CVSS 8.6
HIGH
Risk Summary
Successful exploitation of these vulnerabilities may allow remote code execution, authentication bypass, or privilege escalation.
CVEs (3)
Remediations
- Rockwell Automation recommends users of the affected software update to an available software revision (Connected Components Workbench v13.00.00 or later) that addresses the associated risk. Users who are unable to update are directed towards risk mitigation strategies provided below, and are encouraged, when possible, to combine these with Rockwell Automation's general security guidelines to employ multiple strategies simultaneously.
- Run Connected Components Workbench as a User, not as an Administrator, to minimize the impact of malicious code on the infected system.
- Do not open untrusted .ccwarc, files with Connected Components Workbench. Employ training and awareness programs to educate users on the warning signs of a phishing or social engineering attack.
- Use of Microsoft AppLocker or other similar allow list applications can help mitigate risk. Information on using AppLocker with Rockwell Automation products is available at KnowledgeBase Article QA17329 (login required).
- Ensure the least-privilege user principle is followed, and user/service account access to shared resources (such as a database) is only granted with a minimum number of rights as needed.
- For more information, please see the industrial security advisory from Rockwell Automation.
Affected Vendors
Rockwell Automation
Affected Products (1)
Rockwell Automation
·
Connected Components Workbench
<= 12.00.00
Affected Sectors
Commercial Facilities, Defense Industrial Base, Energy, and Government Facilities
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more