Rockwell RSLogix 5000 Insufficiently Protected Credentials
Rockwell RSLogix 5000 Insufficiently Protected Credentials
Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.
According to Rockwell Automation, new RSLogix 5000 versions, V20.03 and V21.03, have been released that address this vulnerability. These releases include mitigations that enhance password protection. Project files created in earlier affected RSLogix 5000 versions of software must be opened, resaved, and then downloaded to the appropriate controller to mitigate the risk associated with this discovered vulnerability. IMPORTANT: Files with protected content that have been opened and update using enhanced software will no longer be compatible with earlier versions of RSLogix 5000 software. For example, a V20.01 project file with protected content that has been opened and resaved using V20.03 software can only be opened with V20.03 and higher versions of software. Also, a V21.00 project file with protected content that has been opened and resaved using V21.03 software can only be opened with V21.03 and higher versions of software. For the procedure to update project files, please refer to Rockwell Automation Knowledgebase AID:565204 available here: https://rockwellautomation.custhelp.com/app/answers/detail/a_id/565204 . In addition to using current RSLogix 5000 software, Rockwell Automation also recommends the following actions to all concerned customers: * Where possible, adopt a practice to track creation and distribution of protected ACD files, including duplicates and derivatives that contain protected content in the event that these files may need to be found or