ICSA-24-214-09
·
Published 2024-08-01
·
View on CISA ICS-CERT ↗
Rockwell Automation Logix Controllers
CVSS 8.4
HIGH
Risk Summary
Successful exploitation of this vulnerability could allow an attacker to execute CIP programming and configuration commands.
CVEs (1)
Remediations
- Rockwell Automation recommends user update the Logix controllers to the following:
- ControlLogix 5580 (1756-L8z): Update to versions V32.016, V33.015, V34.014,V35.011 and later.
- GuardLogix 5580 (1756-L8zS): Update to versions V32.016, V33.015, V34.014,V35.011 and later.
- 1756-EN4TR: Update to versions V5.001 and later.
- 1756-EN2T Series D, 1756-EN2F Series C, 1756-EN2TR Series C, 1756-EN3TR Series B, and 1756-EN2TP Series A: Update to version V12.001 and later
- The products 1756-EN2T Series A/B/C, 1756-EN2F Series A/B, 1756-EN2TR Series A/B, and 1756-EN3TR Series A do not have a fix available. Users can upgrade to Series D to remediate this vulnerability.
- Users that are using the affected firmware and who are not able to upgrade to one of the corrected versions are encouraged to apply the following mitigation and security best practices, where possible.
- Limit the allowed CIP commands on controllers by setting the mode switch to the RUN position.
- Security Best Practices
Affected Vendors
Rockwell Automation
Affected Products (16)
Rockwell Automation
·
ControlLogix 5580 (1756-L8z)
V28
Rockwell Automation
·
GuardLogix 5580 (1756-L8zS)
V31
Rockwell Automation
·
1756-EN4TR
V2
Rockwell Automation
·
1756-EN2T, Series A/B/C (unsigned version)
v5.007
Rockwell Automation
·
1756-EN2F, Series A/B (unsigned version)
v5.007
Rockwell Automation
·
1756-EN2TR, Series A/B (unsigned version)
v5.007
Rockwell Automation
·
1756-EN3TR, Series A (unsigned version)
v5.007
Rockwell Automation
·
1756-EN2T, Series A/B/C (signed version)
v5.027
Rockwell Automation
·
1756-EN2F, Series A/B (signed version)
v5.027
Rockwell Automation
·
1756-EN2TR, Series A/B (signed version)
v5.027
Rockwell Automation
·
1756-EN3TR, Series A (signed version)
v5.027
Rockwell Automation
·
1756-EN2T, Series D
V10.006
Rockwell Automation
·
1756-EN2F, Series C
V10.009
Rockwell Automation
·
1756-EN2TR, Series C
V10.007
Rockwell Automation
·
1756-EN3TR, Series B
V10.007
Rockwell Automation
·
1756-EN2TP, Series A
V10.020
Affected Sectors
Critical Manufacturing
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more