Rockwell Advises Disconnecting Internet
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-22681 | Authentication Bypass in Rockwell Automation Studio 5000 Logix Designer and Logix PLCs Rockwell Automation's Studio 5000 Logix Designer (versions 21 and later) and RSLogix 5000 (versions 16 through 20) use a shared key to verify that they are communicating with genuine Allen-Bradley Logix controllers, and an unauthenticated remote attacker can bypass this verification mechanism (CWE-522, insufficient protection of credentials). The attack requires only network access to the affected software or controllers - no credentials, no user interaction, and no special conditions (CVSS 3.1: 9.8). By bypassing the verification, an attacker can authenticate to CompactLogix, ControlLogix, DriveLogix, Compact GuardLogix, GuardLogix and SoftLogix controllers and interact with the PLCs, potentially tampering with industrial processes. Any deployment running the affected engineering software versions with the listed Logix controller families is in scope, which spans a very large share of Rockwell's installed base. CISA added this flaw to its Known Exploited Vulnerabilities catalog on 2026-03-05 (ransomware use unknown), and EPSS puts the 30-day exploitation probability at roughly 64%; no public proof-of-concept is known. Do: Apply mitigations per Rockwell's instructions - the vendor has advised disconnecting internet-facing connections, so remove internet exposure from affected controllers and engineering workstations and segment OT networks. Follow applicable CISA BOD 22-01 guidance, and inventory for Studio 5000 Logix Designer v21+ or RSLogix 5000 v16-20 used with the listed controllers; upgrade per vendor guidance or discontinue use if mitigations are unavailable. | 9.8 | 64% | KEV |
| massroughly 1 million or more Logix controller installations (tens of thousands likely internet-exposed) | |
| CVE-2022-1159 | Rockwell Automation Studio 5000 Logix Designer (all versions) are vulnerable when an attacker who achieves administrator access on a workstation running Studio Rockwell Automation Studio 5000 Logix Designer (all versions) are vulnerable when an attacker who achieves administrator access on a workstation running Studio 5000 Logix Designer could inject controller code undetectable to a user. NVD description · AI analysis pending | 7.2 | 3% |
| — | ||
| CVE-2023-3595 | Where this vulnerability exists in the Rockwell Automation 1756 EN2* and 1756 EN3* ControlLogix communication products, it could allow a malicious user to perfo Where this vulnerability exists in the Rockwell Automation 1756 EN2* and 1756 EN3* ControlLogix communication products, it could allow a malicious user to perform remote code execution with persistence on the target system through maliciously crafted CIP messages. This includes the ability to modify, deny, and exfiltrate data passing through the device. NVD description · AI analysis pending | 9.8 | 6% |
| — | ||
| CVE-2023-46290 | Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS user token through the FactoryTalk® Services Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS user token through the FactoryTalk® Services Platform web service and then use the token to log in into FactoryTalk® Services Platform . This vulnerability can only be exploited if the authorized user did not previously log in into the FactoryTalk® Services Platform web service. NVD description · AI analysis pending | 8.1 | 3% |
| — | ||
| CVE-2024-21914 | A vulnerability exists in the affected product that allows a malicious user to restart the Rockwell Automation PanelView™ Plus 7 terminal remotely without secur A vulnerability exists in the affected product that allows a malicious user to restart the Rockwell Automation PanelView™ Plus 7 terminal remotely without security protections. If the vulnerability is exploited, it could lead to the loss of view or control of the PanelView™ product. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2024-21915 | A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, a malicious user with basic user group privileges could potentially sign into the software and receive FTSP Administrator Group privileges. A threat actor could potentially read and modify sensitive data, delete data and render the FTSP system unavailable. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2024-21917 | A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the service token and use it for authenticati A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the service token and use it for authentication on another FTSP directory. This is due to the lack of digital signing between the FTSP service token and directory. If exploited, a malicious user could potentially retrieve user information and modify settings without any authentication. NVD description · AI analysis pending | 9.1 | <1% |
| — |
Full article554 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananMay 22, 2024ICS Security / Vulnerability
Rockwell Automation is urging its customers to disconnect all industrial control systems (ICSs) not meant to be connected to the public-facing internet to mitigate unauthorized or malicious cyber activity.
The company said it's issuing the advisory due to "heightened geopolitical tensions and adversarial cyber activity globally."
To that end, customers are required to take immediate action to determine whether they have devices that are accessible over the internet and, if so, cut off connectivity for those that are not meant to be left exposed.
"Users should never configure their assets to be directly connected to the public-facing internet," Rockwell Automation further added.
"Removing that connectivity as a proactive step reduces attack surface and can immediately reduce exposure to unauthorized and malicious cyber activity from external threat actors."
On top of that, organizations are required to ensure that they have adopted the necessary mitigations and patches to secure against the following flaws impacting their products -
- CVE-2021-22681 (CVSS score: 10.0)
- CVE-2022-1159 (CVSS score: 7.7)
- CVE-2023-3595 (CVSS score: 9.8)
- CVE-2023-46290 (CVSS score: 8.1)
- CVE-2024-21914 (CVSS score: 5.3)
- CVE-2024-21915 (CVSS score: 9.0)
- CVE-2024-21917 (CVSS score: 9.8)
The alert has also been shared by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), which is also recommending that users and administrators follow appropriate measures outlined in the guidance to reduce exposure.
![]() |
| A Web-based PLC Malware |
This includes a 2020 advisory jointly released by CISA and the National Security Agency (NSA) warning of malicious actors exploiting internet-accessible operational technology (OT) assets to conduct cyber activity that could pose severe threats to critical infrastructure.
"Cyber actors, including advanced persistent threat (APT) groups, have targeted OT/ICS systems in recent years to achieve political gains, economic advantages, and possibly to execute destructive effects," the NSA noted in September 2022.
Adversaries have also been observed connecting to publicly-exposed programmable logic controllers (PLCs) and modifying the control logic to trigger undesirable behavior.
In fact, recent research presented by a group of academics from the Georgia Institute of Technology at the NDSS Symposium in March 2024 has found that it's possible to perform a Stuxnet-style attack by compromising the web application (or human-machine interfaces) hosted by the embedded web servers within the PLCs.
This entails exploiting the PLC's web-based interface used for remote monitoring, programming, and configuration in order to gain initial access and then take advantage of the legitimate application programming interfaces (APIs) to sabotage the underlying real-world machinery.
"Such attacks include falsifying sensor readings, disabling safety alarms, and manipulating physical actuators," the researchers said. "The emergence of web technology in industrial control environments has introduced new security concerns that are not present in the IT domain or consumer IoT devices."
The novel web-based PLC Malware has significant advantages over existing PLC malware techniques such as platform independence, ease-of-deployment, and higher levels of persistence, allowing an attacker to covertly perform malicious actions without having to deploy control logic malware.
To secure OT and ICS networks, it's advised to limit exposure of system information, audit and secure remote access points, restrict access to network and control system application tools and scripts to legitimate users, conduct periodic security reviews, and implement a dynamic network environment.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/05/rockwell-advises-disconnecting-internet.html
