QID 590332

Date Published: 2022-07-18

QID 590332: Rockwell Automation Stratix 5100 (Update A) Vulnerability (ICSA-17-299-02)

AFFECTED PRODUCTS
Rockwell Automation reports the vulnerability affects the following wireless access point/workgroup bridge products:
Stratix 5100 Version 15.3(3) JC1 and earlier.

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Rockwell using registry "HKLM\SOFTWARE\Rockwell Software"

Successful exploitation of this vulnerability may allow the attacker to operate as a man-in-the-middle between the device and the wireless network.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-17-299-02 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590332

    Software Advisories
    Advisory ID Software Component Link
    ICSA-17-299-02 URL Logo www.us-cert.gov/ics/advisories/ICSA-17-299-02