PatchSiren cyber security CVE debrief
CVE-2024-6068 Rockwell Automation CVE debrief
CVE-2024-6068 is a memory corruption vulnerability in Rockwell Automation Arena Input Analyzer version v16.20.00 (as included in Arena v16.20.03). The flaw occurs when parsing DFT files and can be exploited by local threat actors to disclose information and execute arbitrary code. Exploitation requires a legitimate user to open a malicious DFT file. The vulnerability was published on November 14, 2024, with a CVSS 3.1 score of 7.3 (HIGH). This is not a Known Exploited Vulnerability (KEV).
- Vendor
- Rockwell Automation
- Product
- Arena Input Analyzer
- CVSS
- HIGH 7.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-11-14
- Original CVE updated
- 2024-11-14
- Advisory published
- 2024-11-14
- Advisory updated
- 2024-11-14
Who should care
Organizations using Rockwell Automation Arena Input Analyzer in industrial control system environments, particularly those processing DFT files from external or untrusted sources. Security teams responsible for OT/ICS asset management and patch management should prioritize this update.
Technical summary
The vulnerability exists in the DFT file parsing functionality of Rockwell Automation Input Analyzer v16.20.00. Memory corruption during parsing can be triggered when a legitimate user opens a crafted malicious DFT file. Successful exploitation enables local threat actors to achieve information disclosure and arbitrary code execution. The attack vector is local, requires low privileges, and depends on user interaction (opening the malicious file). The confidentiality, integrity, and availability impacts are all rated HIGH.
Defensive priority
HIGH
Recommended defensive actions
- Update Arena Input Analyzer to version 16.20.04 or later per vendor guidance.
- Implement security best practices for industrial automation control systems as recommended by Rockwell Automation.
- Review Rockwell Automation's security advisory for additional mitigation information.
- Exercise caution when opening DFT files from untrusted sources.
- Apply defense-in-depth strategies for industrial control systems environments.
Evidence notes
Source: CISA CSAF advisory ICSA-24-319-15. Affected product: Rockwell Automation Arena Input Analyzer <=v16.20.03. Vendor fix available in version 16.20.04 or later.
Official resources
-
CVE-2024-6068 CVE record
CVE.org
-
CVE-2024-6068 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
2024-11-14