news.mlab.sh
Back to the feed
threat-intel

Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix

HighCVSS 7.5
Summary

Rockwell Automation has issued an advisory regarding critical vulnerabilities in its ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, and Compact GuardLogix industrial control systems. These vulnerabilities, identified as CVE-2021-42260 and related, could lead to a denial of service and require a program download for recovery. Rockwell Automation recommends updating to firmware version 34.015 or later to mitigate the risk.

Rockwell Automation has announced a security advisory concerning critical vulnerabilities affecting its ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, and Compact GuardLogix industrial control systems. These vulnerabilities, specifically CVE-2021-42260 and related, are classified as a denial of service risk. Exploitation involves a crafted data attack that can trigger a major nonrecoverable fault (MNRF) in the systems. To recover, a program download is required for non-safety controllers, while stage 2 reset is needed for safety controllers. Rockwell Automation strongly advises users to update their firmware to version 34.015 or later to address these issues. The advisory highlights the importance of minimizing network exposure and isolating control systems from business networks as part of a broader defense-in-depth strategy. CISA recommends organizations implement cybersecurity strategies and proactively monitor for suspicious activity. Rockwell Automation reported these vulnerabilities to CISA. The advisory also includes guidance on avoiding social engineering attacks and utilizing secure remote access methods, such as VPNs.

Read the full article at CISA Advisories