logo

Bypassing Rockwell Automation Logix Controllers’ Local Chassis Security Protection

ID: 80599c05-e8bb-51af-a990-5748a5a315af

STIX ID: report--80599c05-e8bb-51af-a990-5748a5a315af

Feed Name: Claroty Team82

Threat Score
75/100

Date Published: 2024-08-01

Date Updated: 2026-04-17

Author: Sharon Brizinov

...
...

Team82 disclosed CVE-2024-6242: a vulnerability in Rockwell Automation ControlLogix 1756 chassis where CIP routing can be used to 'jump' between local backplane slots and bypass the trusted-slot security, enabling an attacker with network access to send elevated commands (e.g., download logic) to the PLC CPU; Rockwell released a fix and the advisory includes a Snort rule to detect such 'jump' forward-open requests.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.