QID 590342

Date Published: 2022-06-23

QID 590342: Rockwell Automation Allen-Bradley Stratix and ArmorStratix Multiple Vulnerabilities (ICSA-17-208-04)

AFFECTED PRODUCTS
The following versions of Allen-Bradley Stratix and ArmorStratix switches are affected:
All Versions 15.2(5)EA.fc4 and earlier
Allen-Bradley Stratix 5400 Industrial Ethernet Switches
Allen-Bradley Stratix 5410 Industrial Distribution Switches
Allen-Bradley Stratix 5700 and ArmorStratix 5700 Industrial Managed Ethernet Switches
Allen-Bradley Stratix 8000 Modular Managed Ethernet Switches
All Versions 15.6(3)M1 and earlier
Allen-Bradley Stratix 5900 Services Router
All Versions 15.2(4)EA and earlier
Stratix 8300 Modular Managed Ethernet Switches

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Rockwell using registry "HKLM\SOFTWARE\Rockwell Software"

Successful exploitation of these vulnerabilities could allow an authenticated, remote attacker to execute code on an affected system or cause an affected system to crash and reload.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-17-208-04 for affected packages and patching details.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ICSA-17-208-04 URL Logo www.us-cert.gov/ics/advisories/ICSA-17-208-04