Rockwell Automation ControlFLASH

Summary

Rockwell Automation ControlFLASH versions up to V15.07 are affected by a vulnerability (CVE-2026-12663) where the installer grants write permissions to the "Everyone" group on the installation directory. This could allow an attacker to execute arbitrary code with the privileges of the logged-in user.

IFF Assessment

FOE

This vulnerability allows for arbitrary code execution, which is a significant threat to system integrity and confidentiality.

Severity

7.3 High

The CVSS score of 7.3 reflects a high severity due to the 'Missing Authentication for Critical Function' vulnerability, which enables arbitrary code execution with user-level privileges.

Defender Context

This vulnerability in Rockwell Automation ControlFLASH poses a risk to critical infrastructure sectors like manufacturing, energy, and water, as it allows for arbitrary code execution. Defenders should prioritize updating affected systems to version 15.08 or later, and implement the suggested mitigation steps to restrict permissions if an upgrade is not immediately possible.

Read Full Story →