CVE-2024-6242: Rockwell Automation Chassis Restrictions Bypass Vulnerability in Select Logix Devices
A vulnerability exists in Rockwell Automation affected products that allows a threat actor to bypass the Trusted® Slot feature in a ControlLogix® controller. If exploited on any affected module in a 1756 chassis, a threat actor could potentially execute CIP commands that modify user projects and/or device configuration on a Logix controller in the chassis.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6242?
CVE-2024-6242 is classified as a high-severity vulnerability that allows bypassing security features in affected Rockwell Automation products.
How do I fix CVE-2024-6242?
To address CVE-2024-6242, update your Rockwell Automation ControlLogix and Logix controllers to the latest security patches provided by the vendor.
Which products are affected by CVE-2024-6242?
CVE-2024-6242 affects Rockwell Automation ControlLogix controllers and Logix controllers operating in a 1756 chassis.
What happens if CVE-2024-6242 is exploited?
If exploited, CVE-2024-6242 allows a threat actor to execute CIP commands that can alter user configurations in the affected controllers.
Is there a workaround for CVE-2024-6242?
While a specific workaround for CVE-2024-6242 may not be provided, ensuring comprehensive network security measures can help mitigate potential risks.