CVE Vulnerabilities

CVE-2024-6242

Unprotected Alternate Channel

Published: Aug 01, 2024 | Modified: Aug 01, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability exists in Rockwell Automation affected products that allows a threat actor to bypass the Trusted® Slot feature in a ControlLogix® controller. If exploited on any affected module in a 1756 chassis, a threat actor could potentially execute CIP commands that modify user projects and/or device configuration on a Logix controller in the chassis.

Weakness

The product protects a primary channel, but it does not use the same level of protection for an alternate channel.

Potential Mitigations

References