← Back to home
ICSA-24-256-20  ·  Published 2024-09-12  ·  View on CISA ICS-CERT ↗

Rockwell Automation AADvance Trusted SIS Workstation

CVSS 7.8 HIGH

Risk Summary

Successful exploitation of these vulnerabilities could result in an attacker executing code within the context of a current process.

Remediations

  • Rockwell Automation offers users the following solutions:
  • AADvance Trusted SIS Workstation: Update to version 2.00.02 or later
  • Customers using the affected software, who are not able to upgrade to the corrected version, are encouraged to apply security best practices, where possible.
  • Security Best Practices
  • Rockwell Automation Customers using the affected software are encouraged to apply the following additional risk mitigations, if possible:
  • Do not archive or restore projects from unknown sources.
  • For information on how to mitigate Security Risks on industrial automation control systems, we encourage customers to implement our suggested security best practices to minimize the risk of the vulnerability.
  • For more information about this issue, please see the advisory on the Rockwell Automation security page.

Affected Vendors

Rockwell Automation

Affected Products (1)

Rockwell Automation · AADvance Trusted SIS Workstation <=2.00.01

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more