← Back to CVE List
Vulnerability Intelligence Report
Rockwell Automation Chassis Restrictions Bypass Vulnerability in Select Logix Devices

CVE-2024-6242

A vulnerability exists in Rockwell Automation affected products that allows a threat actor to bypass the Trusted® Slot feature in a ControlLogix® controller. If exploited on any affected module in a 1756 chassis, a threat actor could potentially execute CIP commands that modify user projects and/or device configuration on a Logix controller in the chassis.

No Active Exploit Signals
CVSS Base Score
7.3
HIGH
EPSS Probability:9.20%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-420 ↗CWE-420: Unprotected Alternate Channel

Affected Products & Versions

Vendor Product Affected Versions
Rockwell Automation ControlLogix® 5580 (1756-L8z) V28 (affected)
Rockwell Automation GuardLogix® 5580 (1756-L8zS) V31 (affected)
Rockwell Automation 1756-EN4TR V2 (affected)
Rockwell Automation 1756-EN2T v5.007(unsigned)/v5.027(signed) (affected)
Rockwell Automation 1756-EN2F v5.007(unsigned)/v5.027(signed) (affected)
Rockwell Automation 1756-EN2TR v5.007(unsigned)/v5.027(signed) (affected)
Rockwell Automation 1756-EN3TR v5.007(unsigned)/v5.027(signed) (affected)
Rockwell Automation 1756-EN2T 1756-EN2T/D: V10.006 (affected)
Rockwell Automation 1756-EN2F 1756-EN2F/C: V10.009 (affected)
Rockwell Automation 1756-EN2TR 1756-EN2TR/C: V10.007 (affected)
Rockwell Automation 1756-EN3TR 1756-EN3TR/B: V10.007 (affected)
Rockwell Automation 1756-EN2TP 1756-EN2TP/A: V10.020 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
9.197%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityRockwell Automation · Vendor · USA
Reserved2024-06-21T12:21:00
Published2024-08-01T15:15:32
Patch Date2024-08-01
Last Updated2025-09-25T13:34:40

LINK COPIED TO CLIPBOARD