Control & AutomationIndustry news & eventsNews & Events

Vulnerability identified in Rockwell Automation Safety PLC with exploitation resulting in DoS condition

Listen to this article

An Applied Risk researcher has identified a vulnerability in the Rockwell Automation Allen-Bradley CompactLogix 5370 Controller 1769-L30ERMS, which could allow an unauthenticated remote threat-actor to reboot a device and switch it to the “Major Non-Recoverable Fault” mode, resulting in a Denial of Service (DoS) condition. This issue cannot be automatically resolved and requires manual operations to be undertaken by an engineer.

The Safety PLC from Rockwell is commonly used in various industrial sectors and industries, including oil & gas, chemical, manufacturing, water, power and more. The vulnerability is classified as serious and it has been given a CVSS (Common Vulnerability Scoring System) score of 7.5, which is classed as high.

Applied Risk has worked alongside the manufacturer in the responsible disclosure process, and the fix has been issued by the vendor. For end users, updating the product firmware to the latest version Rockwell has provided will fix this vulnerability.

Show More

    Would you like further information about this article?

    Add your details below and we'll be in touch ASAP!


    Input this code: captcha

    Phil Black - PII Editor

    I'm the Editor here at Process Industry Informer, where I have worked for the past 17 years. Please feel free to join in with the conversation, or register for our weekly E-newsletter and bi-monthly magazine here: https://www.processindustryinformer.com/magazine-registration. I look forward to hearing from you!

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    Back to top button

    Join 25,000 process industry specialists and subscribe to:

    PII has a global network of suppliers ready to help...