Rockwell Automation Studio 5000 Logix Designer

Summary

Multiple vulnerabilities have been identified in Rockwell Automation Studio 5000 Logix Designer, allowing local attackers to execute arbitrary files, alter configurations, or execute arbitrary code. These vulnerabilities include path traversal, incorrect authorization, and unquoted search path elements, with the most severe impacting versions as far back as V32.00.

IFF Assessment

FOE

The identification of multiple vulnerabilities that allow for arbitrary code execution and configuration alteration represents a significant risk to industrial control systems, making it bad news for defenders.

Severity

7.5 High

The CVSS score of 7.5 indicates a High severity vulnerability. This is likely due to factors such as the ability to execute arbitrary code, the potential impact on critical infrastructure, and the local attack vector.

Defender Context

Defenders should prioritize patching or mitigating these vulnerabilities in Rockwell Automation Studio 5000 Logix Designer, especially in critical manufacturing environments. The ability for local attackers to achieve code execution means that compromised credentials or local access can lead to severe system compromise.

Read Full Story →