Dragos Enabled Defense Against APT Exploits for Rockwell Automation ControlLogix
ID: 8260745d-1dff-55de-a998-d52a15b3fc6d
STIX ID: report--8260745d-1dff-55de-a998-d52a15b3fc6d
Feed Name: Dragos Blog
Dragos, coordinating with Rockwell Automation and the U.S. government, analyzed an APT-associated exploit capability targeting ControlLogix EtherNet/IP modules (1756-EN2/EN3 — CVE-2023-3595; 1756-EN4 — CVE-2023-3596) that can enable arbitrary firmware memory manipulation and persistence (EN2/EN3) or denial-of-service (EN4). The advisory details potential disruptive impacts to industrial processes, recommends immediate firmware updates and network mitigations, provides detection guidance, and reports no confirmed in-the-wild exploitation as of mid-July 2023.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
