Critical Flaw Exposes Rockwell Automation ControlLogix 1756 to Attack

Critical Flaw Exposes Rockwell Automation ControlLogix 1756 to Attack

Vulnerability Overview

A critical vulnerability in Rockwell Automation’s ControlLogix 1756 series poses a significant risk to industrial control systems (ICS). Identified as CVE-2024-6242, this flaw undermines the trusted slot mechanism designed to prevent unauthorized access.

How the Vulnerability Works

The ControlLogix 1756 chassis contains various components connected via a backplane, with the trusted slot feature controlling communication to authorized slots. However, researchers from Claroty's Team82 discovered that the Common Industrial Protocol (CIP) routing mechanism could be exploited to bypass this security feature. Attackers can manipulate CIP routing to access the controller’s CPU, gaining control over functions typically reserved for authorized devices.

The Impact

Exploitation of this vulnerability could allow attackers to control critical industrial processes, potentially causing severe disruptions. Given the extensive use of ControlLogix 1756 devices across industries, the consequences are far-reaching.

Mitigating the Risk

Rockwell Automation has issued a patch to fix the vulnerability. Users of ControlLogix, GuardLogix, and 1756 ControlLogix I/O Modules should apply this update immediately. Following guidance from the U.S. Cybersecurity and Infrastructure Security Agency (CISA) is also recommended to strengthen system defenses.

Conclusion

This vulnerability underscores the ongoing challenges in securing industrial control systems. While a patch is available, organizations must implement robust security practices, including regular updates, network segmentation, and employee training to protect against new threats.

Model Number Title Link
1756-CNBR Communication Module Allen Bradley Learn More
1756-IB16 Digital DC Input Module Allen Bradley Learn More
1756-OB16D Diagnostic DC Output Module Allen Bradley Learn More
1769-L33ER CompactLogix 2 MB ENET Controller Allen Bradley Learn More
1771-NIS Remote I/O Adapter Module Allen Bradley Learn More
1771-P6R Power Supply Allen Bradley Learn More
1771-P6S Power Supply Allen Bradley Learn More
2711C-T6T PanelView Comp C600 Graphic Terminal Allen Bradley Learn More
2711P-RN3 Communication Module Allen Bradley Learn More
2711P-T6M3D PanelView Plus Terminal Allen Bradley Learn More
1797-BIC I/O Bus Isolator Module Allen Bradley Learn More
1785-L40C15 ControlNet PLC-5 Processor Allen Bradley Learn More
1785-CHBM CNET Backup Cartridge Allen Bradley Learn More
1756-ENET Ethernet Communication Module Allen Bradley Learn More
1756-IB32/B ControlLogix 32 Pt 12-24V DC Digital Input Module Allen Bradley Learn More
1756-IV32 ControlLogix 32 Pt 12-24VDC Digital Input Module Allen Bradley Learn More
1756-CNB/B ControlLogix Communication Module Allen Bradley Learn More
1756-ENBT/A ControlLogix ENET/IP Comms Module Allen Bradley Learn More