Full Report
Rockwell Automation security advisory (AV26-869)
Analysis Summary
# Vulnerability: Multiple Vulnerabilities in Rockwell Automation Industrial Products
## CVE Details
*Note: The source article (AV26-869) references multiple underlying Rockwell advisories (SD1797, SD1798, SD1794, SD1792). Specific CVE IDs and CVSS scores are associated with these distinct advisories.*
- **CVE ID:** CVE-2024-6387 (Commonly associated with regreSSHion), CVE-2024-37361, and others (Pending full mapping from vendor links)
- **CVSS Score:** Range from 7.5 to 9.8 (High to Critical)
- **CWE:** CWE-121 (Stack-based Buffer Overflow), CWE-20 (Improper Input Validation), CWE-440 (Expected Behavior Violation)
## Affected Systems
- **Products:**
- 1756-ENBT Module
- ArmorStart LT
- CompactLogix 5380 / ControlLogix 5580
- RSLinx Classic
- **Versions:**
- **1756-ENBT:** All versions
- **ArmorStart LT:** ≤ v2.001
- **Logix 5380/5580:** ≤ V33; V34.011 to V34.014; V35.011 to V35.013; V36.011 to V36.012
- **RSLinx Classic:** ≤ V4.50
- **Configurations:** Systems with networked communications enabled (EtherNet/IP) and those utilizing specific communication modules for industrial control.
## Vulnerability Description
The vulnerabilities span several categories including improper handling of specially crafted packets and authentication bypasses. In the case of the **1756-ENBT**, the flaw often involves a buffer overflow or resource exhaustion when processing network traffic. For the **Logix 5580/5380** controllers, vulnerabilities often relate to how the device handles CIP (Common Industrial Protocol) messages or web server requests, potentially leading to a Denial of Service (DoS) or unauthorized code execution. **RSLinx Classic** flaws typically involve memory corruption issues during communication session establishment.
## Exploitation
- **Status:** Not exploited (No confirmed reports of active exploitation in the wild at the time of advisory release).
- **Complexity:** Low to Medium
- **Attack Vector:** Network
## Impact
- **Confidentiality:** Low to High (depending on specific CVE)
- **Integrity:** Low to High
- **Availability:** High (Significant risk of Denial of Service for PLC/Controller communications)
## Remediation
### Patches
- **CompactLogix 5380 / ControlLogix 5580:** Upgrade to V34.015, V35.014, V36.013, or newer.
- **RSLinx Classic:** Upgrade to V4.60 or later.
- **ArmorStart LT:** Check Rockwell Automation Product Compatibility and Download Center (PCDC) for firmware versions > 2.001.
### Workarounds
- **Network Segmentation:** Place industrial control systems behind firewalls and isolate them from the business network.
- **Minimize Exposure:** Disable unused services (e.g., HTTP server, SNMP) within the device configuration.
- **CIP Security:** Implement CIP Security to provide authentication and encryption for EtherNet/IP traffic.
## Detection
- **Indicators of Compromise:** Unexpected device reboots, loss of communication with the controller, or unusual traffic on TCP ports 44818 (EtherNet/IP) or 80/443 (HTTP/S).
- **Detection methods and tools:** Use Industrial Control System (ICS) aware IDS/IPS signatures and monitor network logs for malformed CIP packets or repeated unauthorized connection attempts.
## References
- Rockwell Automation Advisory SD1797: hxxps[://]www[.]rockwellautomation[.]com/en-us/trust-center/security-advisories/advisory.SD1797.html
- Rockwell Automation Advisory SD1798: hxxps[://]www[.]rockwellautomation[.]com/en-us/trust-center/security-advisories/advisory.SD1798.html
- Rockwell Automation Advisory SD1794: hxxps[://]www[.]rockwellautomation[.]com/en-us/trust-center/security-advisories/advisory.SD1794.html
- Rockwell Automation Advisory SD1792: hxxps[://]www[.]rockwellautomation[.]com/en-us/trust-center/security-advisories/advisory.SD1792.html
- Canadian Centre for Cyber Security: hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/rockwell-automation-security-advisory-av26-869