CVE-2023-3596: Rockwell Automation Allen-Bradley ControlLogix Communication Modules vulnerable to Denial of Service
Where this vulnerability exists in the Rockwell Automation 1756-EN4 Ethernet/IP communication products, it could allow a malicious user to cause a denial of service by asserting the target system through maliciously crafted CIP messages.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Rockwell Automation 1756-EN4* ControlLogix communications modulesto a version that resolves this vulnerability.Fixed in 5.002 - Configuration
Implement/apply the appended Snort signatures to monitor and detect anomalous Common Industrial Protocol (CIP) packets to Rockwell Automation devices.
Snort detection signatures = append provided signatures - Compensating control
Properly segment ICS/SCADA networks within the process structure and separate them from the Internet and other non-essential networks, since exploitation requires network connectivity to the communications module.
Event History
Frequently Asked Questions
What is CVE-2023-3596?
CVE-2023-3596 is a vulnerability that exists in the Rockwell Automation 1756-EN4* Ethernet/IP communication products.
What is the severity of CVE-2023-3596?
CVE-2023-3596 has a severity value of high.
How does CVE-2023-3596 affect Rockwell Automation 1756-EN4* Ethernet/IP communication products?
CVE-2023-3596 could allow a malicious user to cause a denial of service by asserting the target system through maliciously crafted CIP messages.
Is Rockwell Automation 1756-EN4TR affected by CVE-2023-3596?
Rockwell Automation 1756-EN4TR is affected by CVE-2023-3596.
How can I fix CVE-2023-3596?
To fix CVE-2023-3596, it is recommended to apply the necessary patches or updates provided by Rockwell Automation.