← Back to home
ICSA-22-095-01  ·  Published 2022-04-05  ·  View on CISA ICS-CERT ↗

Rockwell Automation ISaGRAF

CVSS 8.6 HIGH

Risk Summary

Successful exploitation of this vulnerability could allow arbitrary code execution.

CVEs (1)

Remediations

  • Rockwell Automation encourages users to update to v20.00 or later.
  • For the ISaGRAF Workbench and Safety Instrumented Systems Workstation, Rockwell Automation encourages users to use mitigations listed below until a patch is released. More mitigation actions are planned.
  • If an upgrade is not possible or available, users should apply the following mitigations:
  • Run Connected Components Workbench as a User, not as an Administrator, to minimize the impact of malicious code on the infected system.
  • Do not open untrusted files with Connected Component Workbench, ISaGRAF, SISW. Employ training and awareness programs to educate users on the warning signs of a phishing or social engineering attack.
  • Use Microsoft AppLocker or other similar allow list application to help mitigate risk. Information on using AppLocker with Rockwell Automation products is available at KnowledgeBase Article QA17329
  • Ensure the least-privilege user principle is followed, and user/service account access to shared resources (such as a database) is only granted with a minimum number of rights as needed.
  • For more information see Rockwell Automation's security advisory.

Affected Vendors

Rockwell Automation

Affected Products (3)

Rockwell Automation · Connected Component Workbench <= 13.00.00
Rockwell Automation · ISaGRAF Workbench >=6.0 | <= 6.6.9
Rockwell Automation · Safety Instrumented Systems Workstation <= 1.2 (for Trusted Controllers)

Affected Sectors

Multiple Sectors

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more