QID 590349

Date Published: 2022-06-23

QID 590349: Rockwell Automation Stratix 5900 Multiple Vulnerabilities (ICSA-17-094-04)

AFFECTED PRODUCTS
Rockwell Automation reports that these vulnerabilities affect the following Stratix 5900 Services Routers:
Stratix 5900, All Versions prior to 15.6.3.

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Rockwell using registry "HKLM\SOFTWARE\Rockwell Software"

An attacker who exploits these vulnerabilities may be able to perform man-in-the-middle attacks, create denial of service conditions, or remotely execute arbitrary code.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 8.3 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-17-094-04 for affected packages and patching details.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ICSA-17-094-04 URL Logo www.us-cert.gov/ics/advisories/ICSA-17-094-04