Rockwell Automation Logix Platform
Rockwell Automation has issued an advisory regarding a denial-of-service vulnerability in its Logix Platform firmware versions 33 through 36.012. This vulnerability, stemming from improper input length validation during CIP message processing, can lead to a nonrecoverable fault (MNRF) requiring a power cycle. Rockwell recommends updating to firmware version V37.011, V34.015, V35.014, or V36.013 to mitigate the risk. CISA advises minimizing network exposure and isolating control systems from business networks.
Rockwell Automation has issued an advisory regarding a denial-of-service vulnerability in its Logix Platform firmware versions 33 through 36.012. This vulnerability, stemming from improper input length validation during CIP message processing, can lead to a nonrecoverable fault (MNRF) requiring a power cycle. The advisory highlights that the vulnerability is present across Logix, CompactLogix, and GuardLogix platforms. Rockwell Automation recommends updating to firmware version V37.011, V34.015, V35.014, or V36.013 to mitigate the risk. CISA advises minimizing network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. They also recommend locating control system networks and remote devices behind firewalls and isolating them from business networks. For remote access, CISA suggests utilizing more secure methods, such as Virtual Private Networks (VPNs), recognizing that VPNs may have vulnerabilities and should be updated to the most current version available. Additionally, CISA encourages organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures and to implement recommended cybersecurity strategies for proactive defense of ICS assets. Rockwell Automation reported this vulnerability to CISA. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.