PatchSiren cyber security CVE debrief
CVE-2023-40481 7-Zip CVE debrief
CVE-2023-40481 is a high-severity vulnerability affecting Rockwell Automation AADvance Trusted SIS Workstation, published on September 12, 2024. The vulnerability stems from an out-of-bounds write in 7-Zip's SquashFS (SQFS) file parsing functionality, which can be exploited for remote code execution when a user opens a malicious archive or visits a malicious page. The CVSS 3.1 score of 7.8 reflects high impacts to confidentiality, integrity, and availability, with a local attack vector requiring user interaction. Rockwell Automation has released version 2.00.02 to address this issue. Users unable to upgrade should avoid archiving or restoring projects from unknown sources and follow established ICS security best practices.
- Vendor
- 7-Zip
- Product
- AADvance Trusted SIS Workstation
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-09-12
- Original CVE updated
- 2024-09-12
- Advisory published
- 2024-09-12
- Advisory updated
- 2024-09-12
Who should care
Organizations operating Rockwell Automation AADvance Trusted SIS Workstations in industrial safety instrumented systems (SIS) environments. OT security teams, ICS engineers, and plant operators responsible for maintaining safety system integrity should prioritize this patch due to the potential for remote code execution in critical safety infrastructure.
Technical summary
The vulnerability exists in 7-Zip's SquashFS file parser due to insufficient validation of user-supplied data during SQFS analysis. A malformed archive can trigger a write operation beyond allocated buffer boundaries, enabling arbitrary code execution in the context of the current process. Exploitation requires user interaction through opening a malicious file or visiting a malicious page. The vulnerability affects AADvance Trusted SIS Workstation versions 2.00.01 and earlier, which bundle the vulnerable 7-Zip component for archive operations.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade AADvance Trusted SIS Workstation to version 2.00.02 or later to remediate the 7-Zip SquashFS parsing vulnerability.
- If immediate patching is not feasible, avoid archiving or restoring projects from unknown or untrusted sources.
- Implement ICS security best practices including network segmentation, least privilege access, and monitoring for suspicious file activity.
- Review and apply Rockwell Automation's published security guidance for industrial control systems.
Evidence notes
CVE published and modified 2024-09-12 per CISA CSAF advisory ICSA-24-256-20. Affected product: AADvance Trusted SIS Workstation versions <=2.00.01. Vendor fix available in version 2.00.02 or later.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-40481 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-40481
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-40481 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-40481
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-256-20.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-256-20
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.