Rockwell Automation Logix Controllers Vulnerable to Security Bypass Flaw

August 3, 2024
1 min read

TLDR:

Key Points:

  • A high-severity security bypass vulnerability, CVE-2024-6242, was found in Rockwell Automation Logix controllers.
  • The vulnerability allows threat actors to bypass the Trusted Slot feature in ControlLogix controllers, potentially modifying user projects and configurations.

Article Summary:

Organizations using certain Logix PLCs made by Rockwell Automation were alerted to a high-severity security bypass vulnerability discovered by Claroty researchers. The flaw, tracked as CVE-2024-6242, was found in ControlLogix 1756 devices, impacting GuardLogix and other controllers as well. Patches and mitigations have been released. The attack involves exploiting the trusted slot feature to bypass security boundaries, allowing threat actors to execute elevated commands. Although the vulnerability requires network access to the device, it could have serious implications, requiring immediate action by affected organizations.

Latest from Blog

Top 20 Linux Admin Tools for 2024

TLDR: Top Linux Admin Tools in 2024 Key points: Linux admin tools streamline system configurations, performance monitoring, and security management. Popular Linux admin tools include Webmin, Puppet, Zabbix, Nagios, and Ansible. Summary

Bogus job tempts aerospace, energy workers

TLDR: A North Korean cyberespionage group is posing as job recruiters to target employees in aerospace and energy sectors. Mandiant reports that the group uses fake job descriptions stored in malicious archives

Cyber insurance changes shape of security for good and bad

TLDR: Key Points: Cyber-insurance landscape is shifting to encourage greater cyber resiliency Rising costs of cyberattacks are prompting insurers to re-examine underwriting How Cyber-Insurance Shifts Affect the Security Landscape The article discusses