Software: RSLogix 5000® software v16-20, Studio 5000 Logix Designer® v21 and later, and corresponding Logix controllers running these versions.
FactoryTalk® Security, part of the FactoryTalk® Services Platform, if configured and deployed v2.10 and later.
Controllers: 1768 CompactLogix® 1769 CompactLogix® CompactLogix® 5370 CompactLogix® 5380 CompactLogix® 5480 ControlLogix® 5550 ControlLogix® 5560 ControlLogix® 5570 ControlLogix® 5580 ControlLogix® 5590 DriveLogix™ 5730 FlexLogix™ 1794-L34 Compact GuardLogix® 5370 Compact GuardLogix® 5380 GuardLogix® 5560 GuardLogix® 5570 GuardLogix® 5580 SoftLogix™ 5800
FactoryTalk® Security allows a controller to be bound to a security authority which manages configuration of role-based access control. If FactoryTalk® Security and CIP Security are both configured, binding a controller to a FactoryTalk® Security Authority significantly reduces the likelihood that this vulnerability could be used to circumvent role‑based access controls.
If it is not feasible in your environment to deploy CIP Security to protect the connection between programming workstations and controllers, other mitigations and detection strategies can be applied. For details of all mitigation options, please see the table below.
Product Family and Version
Risk Mitigation and Recommended User Actions
ControlLogix® 5590 v38 or later.
If the above cannot be deployed, the followings mitigations are recommended:
ControlLogix® 5580 v32 or later.
If the above cannot be deployed, the followings mitigations are recommended:
ControlLogix® 5580 v31
If the above cannot be deployed, the following mitigations are recommended:
ControlLogix® 5570 v31 or later.
If the above cannot be deployed, the following mitigations are recommended:
CompactLogix® 5380 v28 or later.
If the above cannot be deployed, the following mitigations are recommended:
CompactLogix® 5370 v20 or later
If the above cannot be deployed, the following mitigations are recommended:
ControlLogix® 5580 v28-v30 ControlLogix® 5570 v18 or later ControlLogix® 5560 v16 or later ControlLogix® 5550 v16 GuardLogix® 5580 v31 or later GuardLogix® 5570 v20 or later GuardLogix® 5560 v16 or later 1768 CompactLogix® v16 or later 1769 CompactLogix® v16 or later CompactLogix® 5480 v32 or later Compact GuardLogix® 5370 v28 or later Compact GuardLogix® 5380 v31 or later FlexLogix™ 1794-L34 v16 DriveLogix™ 5370 v16 or later
Customers can refer to the Converged Plantwide Ethernet (CPwE) Design and Implementation Guide (Publication ENET-TD001E) for best practices for deploying network segmentation and broader defense in depth strategies. Customers can also refer to the Rockwell Automation System Security Design Guidelines (Publication secure-rm001) on how to use Rockwell Automation products to improve the security of their industrial automation systems. CIP Security mitigates this vulnerability as it provides the ability to deploy TLS and DTLS based secure communications to supported products. CIP Security is an enhancement to the ODVA EtherNet/IP industrial communication standard and directly addresses the vulnerability noted in this disclosure. CIP Security allows for users to leverage and manage certificates and/or pre-shared keys and does not make use of any hardcoded keys. As of May 5, 2021, a new mitigation option is now available. The 1783-CSP CIP Security Proxy is a standalone hardware solution that provides CIP Security for devices that do not natively support CIP Security. See below for how this product can be deployed to address CompactLogix® based applications. Customers requiring setup or deployment guidance for CIP Security protocol should refer to the CIP Security deployment refence guide (Publication secure-at001) for more information. *Refer to our Industrial Network Architectures Page for comprehensive information implementing validated architectures designed to complement security solutions. See the Network Services Overview Page for information on network and security services for Rockwell Automation to enable assessment, design, implementation and management of validated, secure network architectures. We also recommend that concerned customers continue to monitor this advisory by subscribing to PSA/PN/Security Notifications. This can be done by updating settings in Account Overview within the Knowledgebase. Rockwell Automation remains committed to making security enhancements to our systems in the future. For more information and for assistance with assessing the state of security of your existing control system, including improving your system-level security when using Rockwell Automation and other vendor controls products, you can visit the Rockwell Automation Security Solutions web site. Requests for additional information can be sent to the RASecure Inbox ( [email protected] ). ADDITIONAL LINKS
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
