RSLogix™ 5 and RSLogix 500® Remote Code Execution Via VBA Embedded Script
CVE-2024-7847
Key Information:
- Vendor
Rockwell Automation
- Vendor
- CVE Published:
- 14 October 2024
What is CVE-2024-7847?
A vulnerability exists in Rockwell Automation's software products that permits the execution of arbitrary code via a maliciously crafted project file. The affected feature allows users to prepare project files containing embedded VBA scripts. When a user opens an infected RSP/RSS project file, the script can execute without user interaction, potentially leading to unauthorized remote code execution. This exploitation can affect the integrity of connected devices and systems. Organizations utilizing affected versions should take immediate steps to mitigate risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
RSLogix 500® All
RSLogix™ 5 All
RSLogix™ Micro Developer and Starter All
References
CVSS V3.1
Timeline
Vulnerability published