news.mlab.sh
Back to the feed
vulnerability

Rockwell Automation Redundancy Module Configuration Tool

HighCVSS 7.0
Summary

Rockwell Automation has released a security advisory regarding a vulnerability in its Redundancy Module Configuration Tool. This vulnerability allows a local attacker to place a malicious DLL in a writable directory and, when the tool is run by an administrator, the DLL is loaded and executed with elevated privileges. Users running versions 9.00.00 through 10.00.00 should upgrade to version 10.01.00, or follow Rockwell Automation's security best practices if upgrading is not possible. CISA recommends minimizing network exposure and isolating control systems.

Rockwell Automation has issued a security advisory concerning a vulnerability within its Redundancy Module Configuration Tool. The tool’s functionality involves searching for required DLLs in system paths, and if one or more of these directories are writable by non-administrator users, a local attacker can place a malicious DLL in such a directory. Subsequently, when an administrator runs the tool, the malicious DLL is loaded into the elevated process and executed with Administrator/SYSTEM privileges. This allows an attacker to gain significant control over the system. The vulnerability affects versions 9.00.00 through 10.00.00 of the Redundancy Module Configuration Tool. Rockwell Automation recommends that users running these versions upgrade to version 10.01.00. If upgrading is not feasible, users should implement Rockwell Automation’s security best practices, which can be found at https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight. CISA advises organizations to minimize network exposure for all control system devices and isolate them from business networks. They also recommend using more secure remote access methods, such as VPNs, recognizing that VPNs themselves can have vulnerabilities. CISA encourages organizations to perform thorough impact analysis and risk assessments before deploying defensive measures and provides additional guidance and recommended practices on their ICS webpage at cisa.gov/ics.

Read the full article at CISA Advisories