QID 590338

Date Published: 2022-06-23

QID 590338: Rockwell Automation Stratix and ArmorStratix Switches Multiple Vulnerabilities (ICSA-18-107-04)

AFFECTED PRODUCTS
The following versions of Allen-Bradley Stratix and ArmorStratix Switches use a vulnerable version of Cisco IOS or IOS XE:
Allen-Bradley Stratix 5400 Industrial Ethernet Switches, versions 15.2(6)E0a and earlier;
Allen-Bradley Stratix 5410 Industrial Distribution Switches, versions 15.2(6)E0a and earlier;
Allen-Bradley Stratix 5700 Industrial Managed Ethernet Switches, versions 15.2(6)E0a and earlier;
Allen-Bradley Stratix 8000 Modular Managed Ethernet Switches, versions 15.2(6)E0a and earlier;
Allen-Bradley ArmorStratix 5700 Industrial Managed Ethernet Switches for extreme environments, versions 15.2(6)E0a and earlier.
Updates for all affected products are now available and linked in the Mitigation section below.

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Rockwell using registry "HKLM\SOFTWARE\Rockwell Software"

Successful exploitation of these vulnerabilities could result in loss of availability, confidentiality, and/or integrity caused by memory exhaustion, module restart, information corruption, and/or information exposure.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-18-107-04 for affected packages and patching details.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ICSA-18-107-04 URL Logo www.us-cert.gov/ics/advisories/ICSA-18-107-04