RSLogix™ 5 and RSLogix 500® Remote Code Execution Via VBA Embedded Script
CVE-2024-7847
7.7HIGH
Key Information:
- Vendor
- Rockwell Automation
- Vendor
- CVE Published:
- 14 October 2024
Summary
A vulnerability exists in Rockwell Automation's software products that permits the execution of arbitrary code via a maliciously crafted project file. The affected feature allows users to prepare project files containing embedded VBA scripts. When a user opens an infected RSP/RSS project file, the script can execute without user interaction, potentially leading to unauthorized remote code execution. This exploitation can affect the integrity of connected devices and systems. Organizations utilizing affected versions should take immediate steps to mitigate risks associated with this vulnerability.
Affected Version(s)
RSLogix 500® All
RSLogix™ 5 All
RSLogix™ Micro Developer and Starter All
References
CVSS V3.1
Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Credit
Sharon Brizinov of Claroty Research - Team82