news.mlab.sh
Back to the feed
vulnerability

Rockwell Automation ControlFLASH

HighCVSS 7.0
Summary

Rockwell Automation ControlFLASH versions up to V15.07 are vulnerable to a security flaw that could allow an attacker to execute arbitrary code on a target machine. The vulnerability stems from excessive permissions granted during installation, and while no public exploitation has been reported, Rockwell Automation has released a patch. Users unable to upgrade should remove the ‘Everyone’ group from the ControlFLASH installation directory to mitigate the risk.

A security vulnerability exists within Rockwell Automation ControlFLASH, affecting versions up to V15.07. This vulnerability allows an attacker to execute arbitrary code on a target machine, with the ability to run commands and code of their choice at the logged-in user's permission level. The issue arises because the installer grants excessive write permissions to the ‘Everyone’ group during a product installation. Rockwell Automation has addressed this issue with software version 15.08.

Critical Infrastructure Sectors, including Critical Manufacturing, Energy, and Water and Wastewater, are potentially impacted by this vulnerability, with deployment occurring worldwide. Rockwell Automation’s headquarters are located in the United States.

The vulnerability is classified as CWE-306 Missing Authentication for Critical Function.

Rockwell Automation reported this vulnerability to CISA. Users who cannot upgrade to version 15.08 should follow these mitigation steps: Right-click the C:\Program Files (x86)\ControlFLASH\0001 folder, select Properties, go to the Security tab, and select Edit. In the Permissions for 0001 dialog, select ‘Everyone’ and select ‘Remove’.

CISA recommends organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures, and to implement recommended cybersecurity strategies for proactive defense of ICS assets. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages.

Read the full article at CISA Advisories