Rockwell Logix Controllers Unprotected Alternate Channel (CVE-2024-6242)

high Tenable OT Security Plugin ID 502361

Synopsis

The remote OT asset is affected by a vulnerability.

Description

A vulnerability exists in the affected products that allows a threat actor to bypass the Trusted Slot feature in a ControlLogix controller.
If exploited on any affected module in a 1756 chassis, a threat actor could potentially execute CIP commands that modify user projects and/or device configuration on a Logix controller in the chassis.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

The following text was originally created by the Cybersecurity and Infrastructure Security Agency (CISA). The original can be found at CISA.gov.

Rockwell Automation recommends users update the Logix controllers to the following:

ControlLogix 5580 (1756-L8z): Update to versions V32.016, V33.015, V34.014, V35.011 and later.
GuardLogix 5580 (1756-L8zS): Update to versions V32.016, V33.015, V34.014, V35.011 and later.
1756-EN4TR: Update to versions V5.001 and later.

1756-EN2T Series D, 1756-EN2F Series C, 1756-EN2TR Series C, 1756-EN3TR Series B, and 1756-EN2TP Series A: Update to version V12.001 and later

The products 1756-EN2T Series A/B/C, 1756-EN2F Series A/B, 1756-EN2TR Series A/B, and 1756-EN3TR Series B do not have a fix available. Users can upgrade to Series D to remediate this vulnerability.

Users that are using the affected firmware and who are not able to upgrade to one of the corrected versions are encouraged to apply the following mitigation and security best practices, where possible:

Limit the allowed CIP commands on controllers by setting the mode switch to the RUN position.

See Also

http://www.nessus.org/u?97871567

https://www.cisa.gov/news-events/ics-advisories/icsa-24-214-09

Plugin Details

Severity: High

ID: 502361

Version: 1.4

Type: remote

Family: Tenable.ot

Published: 8/8/2024

Updated: 9/4/2024

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: High

Score: 8.1

CVSS v3

Risk Factor: High

Base Score: 8.4

Temporal Score: 7.3

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:rockwellautomation:1756-en3tr_series_a_firmware, cpe:/o:rockwellautomation:1756-en2f_series_a_firmware, cpe:/o:rockwellautomation:1756-en2tk_series_c_firmware, cpe:/o:rockwellautomation:1756-en4tr_firmware, cpe:/o:rockwellautomation:1756-en2t_series_b_firmware, cpe:/o:rockwellautomation:1756-en2tk_series_d_firmware, cpe:/o:rockwellautomation:1756-en2f_series_c_firmware, cpe:/o:rockwellautomation:1756-en2f_series_b_firmware, cpe:/o:rockwellautomation:1756-en2t_series_a_firmware, cpe:/o:rockwellautomation:1756-en2t_series_c_firmware, cpe:/o:rockwellautomation:1756-en2tr_series_a_firmware, cpe:/o:rockwellautomation:1756-en3tr_series_b_firmware, cpe:/o:rockwellautomation:1756-en2fk_series_a_firmware, cpe:/o:rockwellautomation:1756-en2t_series_d_firmware, cpe:/o:rockwellautomation:1756-en2tk_series_a_firmware, cpe:/o:rockwellautomation:1756-en2tr_series_b_firmware, cpe:/o:rockwellautomation:1756-en2tk_series_b_firmware, cpe:/o:rockwellautomation:guardlogix_5580_firmware, cpe:/o:rockwellautomation:1756-en2tp_series_a_firmware, cpe:/o:rockwellautomation:controllogix_5580_firmware, cpe:/o:rockwellautomation:1756-en2fk_series_b_firmware, cpe:/o:rockwellautomation:1756-en2fk_series_c_firmware, cpe:/o:rockwellautomation:1756-en2tr_series_c_firmware

Required KB Items: Tenable.ot/Rockwell

Exploit Ease: No known exploits are available

Patch Publication Date: 8/1/2023

Vulnerability Publication Date: 8/1/2024

Reference Information

CVE: CVE-2024-6242

CWE: 420

IAVB: 2024-B-0106

ICSA: 24-214-09