Advisory Details
-
Issue Date:
April 17, 2024
-
Importance
High
-
Summary
Rockwell ControlLogix and GuardLogix Vulnerability
-
Systems Impacted
All OT/ICS Environments
On April 11th 2024, Rockwell Automation reported a new vulnerability CVE-2024-3493 affecting ControlLogix 5580, GuardLogix 5580, CompactLogix 5380, and 1756-EN4TR Rockwell Automation products. A specific malformed fragmented packet type can cause a major nonrecoverable fault. If exploited, affected products will become unavailable and require a manual restart to recover them. Major nonrecoverable faults created from vulnerabilities like this could result in loss of view or control of associated devices in your OT Environment.
📝 Affected Devices / Firmware Version(s)
ControlLogix 5580 / V35.011, GuardLogix 5580 / V35.011, CompactLogix 5380 / V35.011, and 1756-EN4TR / V5.001
Actions and/or Recommendations
- Determine if CVE-2024-3493 impacts current OT hardware assets.
- Engage Mangan Cybersecurity for assistance and ensure projects moving forward are managing this CVE.
- Upgrade to the latest version(s) of device firmware. ControlLogix® 5580, GuardLogix 5580, CompactLogix 5380 models will need to be upgraded to firmware version(s) V35.013 or V36.011 at minimum. 1756-EN4TR models will need to be upgraded to firmware version V6.001 at minimum. You can find the latest Rockwell firmware updates here.
- Develop comprehensive understanding of normal operations, controls, and data acquisition needs. Include business continuity objectives as well as return to normal targets that minimize safety, operational, and business interruptions.
- Develop a monitoring strategy to identify undesired access or activity on impacted systems.
- Users unable to upgrade device firmware(s) are encouraged to implement OT Cybersecurity “Best Practices”.
About REAL Matters and Mangan Inc.
REAL Matters advisories are published to communicate cybersecurity threats and risks within the Operational Technology (OT) environment and where Critical Infrastructure vulnerabilities are identified. The purpose of this newsletter is to inform, propose suggested approaches to mitigate the risk as well as provide feedback on how Mangan Cybersecurity is approaching the issue(s) addressed.
Mangan Inc. is a nationally-recognized Specialty Engineering, Automation, and Integration company, providing a full-range of services to the Oil & Gas, Refining, Pipeline, Chemicals, and Life Sciences Industries. Established in Long Beach, California in 1990, Mangan’s multiple office locations include sites in California, Georgia, New Hampshire, North Carolina, Texas, and Louisiana. Mangan’s 350+ employee-owners bring expertise, innovation, and safety as their core mission to some of the largest companies in the world.