CVE-2024-6325: Rockwell Automation Unsecured Private Keys in FactoryTalk® System Services
The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and CVE-2022-1161 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1585.html by implementing CIP security and did not update to the versions of the software CVE-2022-1161 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1585.html and CVE-2022-1161. https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1585.html
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Rockwell Automation FactoryTalk Policy Managerto a version that resolves this vulnerability.Fixed in 6.40 - Operational
Invalidate existing vulnerable private keys/digital certificates and regenerate new secure ones (per Rockwell Automation Trust Center guidance in advisory PN1585).
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6325?
The severity of CVE-2024-6325 is classified as High.
How do I fix CVE-2024-6325?
To fix CVE-2024-6325, you should upgrade Rockwell Automation FactoryTalk® Policy Manager to version 6.40.1 or later.
What are the risks associated with CVE-2024-6325?
The risks associated with CVE-2024-6325 include potential unauthorized access and compromise of sensitive configurations.
Which software versions are affected by CVE-2024-6325?
CVE-2024-6325 affects Rockwell Automation FactoryTalk® Policy Manager version 6.40.0.
Is CVE-2024-6325 being exploited in the wild?
As of now, there is no publicly available information indicating CVE-2024-6325 is actively being exploited in the wild.