AI Security AI安全 23h ago Updated 16h ago 更新于 16小时前 38

Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products 罗克韦尔自动化修复跨产品十余项漏洞

Rockwell Automation disclosed patches or workarounds for over a dozen vulnerabilities across its industrial automation product line Four critical/high-severity DoS vulnerabilities in RSLinx Classic communications software are the only critical findings, causing service crashes requiring restart A high-severity remote code execution flaw was fixed in FactoryTalk Historian, and an authenticated privilege escalation vulnerability was resolved in FactoryTalk Activation Manager Multiple XSS vulnerabi Rockwell Automation发布安全公告,披露其工业自动化产品中存在十余个安全漏洞,已提供补丁或变通方案 最严重的是RSLinx Classic通信软件的四个严重/高严重性DoS漏洞,可导致服务崩溃需重启恢复 FactoryTalk Historian存在高严重性远程代码执行漏洞,FactoryTalk Activation Manager存在权限提升漏洞 CVE-2026-9637被Rockwell标记为"已利用",但CISA官方公告表示未发现实际利用情况,可能存在标注错误 漏洞还涉及ArmorStart控制器XSS、ControlFLASH固件工具任意代码执行、冗余模块配置工具权

55
Hot 热度
60
Quality 质量
50
Impact 影响力

Analysis 深度分析

TL;DR

  • Rockwell Automation disclosed patches or workarounds for over a dozen vulnerabilities across its industrial automation product line
  • Four critical/high-severity DoS vulnerabilities in RSLinx Classic communications software are the only critical findings, causing service crashes requiring restart
  • A high-severity remote code execution flaw was fixed in FactoryTalk Historian, and an authenticated privilege escalation vulnerability was resolved in FactoryTalk Activation Manager
  • Multiple XSS vulnerabilities and a DoS issue were patched in ArmorStart Distributed Motor Controllers
  • ControlFLASH firmware management utility and Redundancy Module Configuration Tool were found vulnerable to arbitrary code execution and privilege escalation, respectively

Why It Matters

This is significant for industrial cybersecurity practitioners because Rockwell Automation products form the backbone of many critical manufacturing and infrastructure systems in North America. The disclosure of remote code execution and privilege escalation flaws in widely deployed industrial software underscores the ongoing attack surface expansion in OT environments, where patching cycles are typically slower than in IT. The CISA co-publication signals heightened government attention to industrial control system vulnerabilities.

Technical Details

  • RSLinx Classic: Four critical/high-severity DoS vulnerabilities (CVE-2026-9637 series) that crash the service upon exploitation; patches or workarounds are available
  • ControlLogix and CompactLogix controllers: CVE-2026-9637, a high-severity DoS flaw; Rockwell initially flagged it as exploited but CISA advisory states no known exploitation; likely a documentation error
  • FactoryTalk Historian Machine Edition: High-severity remote code execution vulnerability patched
  • FactoryTalk Activation Manager: High-severity authenticated privilege escalation flaw allowing access to files, processes, and system resources with elevated privileges
  • ArmorStart Distributed Motor Controllers: Multiple cross-site scripting (XSS) vulnerabilities enabling malicious script execution, plus a DoS issue affecting the web server
  • ControlFLASH firmware management utility: Vulnerability allowing arbitrary code execution at the logged-in user's permission level
  • Redundancy Module Configuration Tool: High-severity privilege escalation flaw
  • 1756-ENBT and Logix controllers (third-party component): DoS vulnerabilities addressed

Industry Insight

  • Organizations running Rockwell Automation infrastructure should prioritize patching RSLinx Classic and FactoryTalk Historian immediately, as these represent the highest-severity exposure with potential for service disruption and remote code execution
  • The discrepancy between Rockwell's and CISA's exploitation status for CVE-2026-9637 highlights the importance of cross-referencing vendor advisories with government cybersecurity bulletins before assuming threat posture
  • The concentration of flaws in configuration and firmware management tools (ControlFLASH, Redundancy Module Configuration Tool) suggests that supply chain and maintenance interfaces remain an underappreciated attack vector in OT environments, warranting stricter access controls and network segmentation

TL;DR

  • Rockwell Automation发布安全公告,披露其工业自动化产品中存在十余个安全漏洞,已提供补丁或变通方案
  • 最严重的是RSLinx Classic通信软件的四个严重/高严重性DoS漏洞,可导致服务崩溃需重启恢复
  • FactoryTalk Historian存在高严重性远程代码执行漏洞,FactoryTalk Activation Manager存在权限提升漏洞
  • CVE-2026-9637被Rockwell标记为"已利用",但CISA官方公告表示未发现实际利用情况,可能存在标注错误
  • 漏洞还涉及ArmorStart控制器XSS、ControlFLASH固件工具任意代码执行、冗余模块配置工具权限提升等多个组件

为什么值得看

本文对工业控制系统(ICS)安全从业者具有重要参考价值,特别是使用Rockwell Automation产品的企业需立即评估风险并应用补丁。CISA同步发布 advisory 表明该漏洞已引起美国政府机构关注,可能成为后续攻击的利用目标。

技术解析

  • RSLinx Classic DoS漏洞:四个严重/高严重性拒绝服务漏洞,可导致通信服务崩溃,需手动重启恢复
  • CVE-2026-9637:ControlLogix和CompactLogix控制器的高严重性DoS漏洞,Rockwell标注为"已利用"但CISA表示未发现利用,存在信息不一致
  • FactoryTalk Historian远程代码执行:高严重性漏洞,允许攻击者远程执行任意代码
  • FactoryTalk Activation Manager权限提升:认证攻击者可访问文件、进程和系统资源并获得提升权限
  • ControlFLASH固件管理工具:存在任意代码执行漏洞,攻击者可在登录用户权限级别执行任意命令
  • 其他受影响组件:1756-ENBT、Logix控制器(第三方组件)、FactoryTalk Historian Machine Edition的DoS漏洞,ArmorStart分布式电机控制器的XSS漏洞

行业启示

  • 工业控制系统供应商需建立更严格的安全公告审核机制,避免Rockwell与CISA公告信息不一致导致用户困惑
  • 建议ICS运维团队优先更新RSLinx Classic和FactoryTalk系列软件,并审查CISA最新 advisory
  • 本文提及的"AI移植PLC漏洞利用"实验表明,工业漏洞利用门槛正在降低,企业应加强自动化产品的安全监测和漏洞管理流程

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全