Tag: Unauthorized Access

Critical Flaw in Rockwell Automation Devices Allows Unauthorized Access
News

Critical Flaw in Rockwell Automation Devices Allows Unauthorized Access

It has been discovered that Rockwell Automation ControlLogix 1756 devices have a high-severity security bypass vulnerability that might be used to carry out programming and configuration commands for the common industrial protocol (CIP). With the CVE identifier CVE-2024-6242, the vulnerability has an 8.4 CVSS v3.1 score. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) stated in an advisory that "a threat actor can circumvent the Trusted Slot feature in a ControlLogix controller by exploiting a vulnerability present in the affected products." A threat actor may be able to utilize any compromised module in a 1756 chassis to carry out CIP commands that alter user projects and/or device configuration on a Logix controller located within the chassis read more about Cr...