Rockwell Automation has announced the release of patches and workarounds addressing over a dozen vulnerabilities found in its industrial automation products. These updates aim to enhance the security of systems widely used in industrial settings.
Critical Vulnerabilities in RSLinx Classic
The latest advisories highlight several critical and high-severity vulnerabilities, particularly within the RSLinx Classic communications software. These denial-of-service (DoS) vulnerabilities pose a significant threat as they can lead to system crashes, necessitating a restart to resume normal operations.
Among these, the advisory for CVE-2026-9637 in ControlLogix and CompactLogix controllers initially listed the flaw as exploited. However, this appears to be a documentation error, as no confirmed exploitations have been reported. A similar stance is maintained by CISA, which also released advisories on the same day.
Additional Security Enhancements
Rockwell has also addressed DoS vulnerabilities in other products, including 1756-ENBT and Logix controllers, by applying necessary patches. In FactoryTalk Historian Machine Edition, a high-severity remote code execution vulnerability has been fixed, enhancing the software’s defense against potential cyber threats.
Furthermore, FactoryTalk Activation Manager received an update to mitigate a high-severity flaw that could allow authenticated users to gain unauthorized access to files and system resources.
Addressing XSS and Privilege Escalation Risks
In addition to software patches, Rockwell Automation has resolved multiple cross-site scripting (XSS) vulnerabilities in ArmorStart Distributed Motor Controllers, which previously could have led to the execution of malicious scripts. A denial-of-service issue affecting the web server component has also been fixed.
The ControlFLASH firmware management utility was updated to prevent arbitrary code execution, which could have allowed attackers to execute commands at the permission level of the logged-in user. A privilege escalation flaw in the Redundancy Module Configuration Tool has been rectified as well.
These updates underscore the ongoing efforts by Rockwell Automation to secure their products against potential cyber threats, ensuring the reliability and safety of industrial operations. As cyber threats continue to evolve, maintaining up-to-date security measures is essential for safeguarding critical infrastructure.
