PatchSiren cyber security CVE debrief
CVE-2024-6325 Rockwell Automation CVE debrief
Rockwell Automation FactoryTalk System Services and FactoryTalk Policy Manager version 6.40 insecurely stores private keys with read and execute permissions granted to the Windows 'Everyone' group. These keys are used to generate digital certificates and pre-shared keys for CIP Security and OPC UA communications. A malicious user with local access to the affected machine could obtain these private keys and impersonate resources on the secured network. The vulnerability was published on July 11, 2024, and carries a CVSS 3.1 score of 6.5 (Medium severity).
- Vendor
- Rockwell Automation
- Product
- FactoryTalk System Services
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-07-11
- Original CVE updated
- 2024-07-11
- Advisory published
- 2024-07-11
- Advisory updated
- 2024-07-11
Who should care
Organizations operating Rockwell Automation FactoryTalk System Services or FactoryTalk Policy Manager v6.40 in industrial environments, particularly those utilizing CIP Security or OPC UA for device authentication and encrypted communications. Asset owners in critical manufacturing, energy, water/wastewater, and other OT sectors where device impersonation could lead to process manipulation or unauthorized network access. Security teams responsible for certificate lifecycle management in ICS environments. Compliance officers addressing NERC CIP, IEC 62443, or similar industrial cybersecurity frameworks requiring proper key protection.
Technical summary
The vulnerability stems from improper file system permissions on cryptographic key material in FactoryTalk System Services v6.40. The keystore directory and PSKs.json file are created with ACLs granting read and execute access to the Windows 'Everyone' group, allowing any authenticated user on the system to extract private keys. These keys serve as trust anchors for CIP Security (Common Industrial Protocol Security) and OPC UA certificate generation. Successful key extraction enables certificate forgery and impersonation of industrial devices on the secured network. The attack requires local access to the Windows host running FactoryTalk components, with no user interaction needed. The confidentiality impact is rated High due to exposure of cryptographic keys, while integrity and availability impacts are None. The scope is Changed as the vulnerability affects resources beyond the vulnerable component's security authority. Remediation involves both software update and manual key rotation procedures to invalidate potentially compromised material.
Defensive priority
high
Recommended defensive actions
- Upgrade FactoryTalk System Services and FactoryTalk Policy Manager to version 6.40.01
- Prior to upgrade, document all Zone and Conduit security settings in FactoryTalk Policy Manager for recreation
- Remove deployed security policies from all devices and reset endpoints to 'Unassigned' Zone
- Delete the FTSS_backup folder at c:ProgramDataRockwellRNAServerGlobalRnaStoreFTSS_Backup
- Delete the keystore folder at c:ProgramDataRockwell AutomationFactoryTalk System Serviceskeystore and any backup copies with timestamped suffixes
- Delete the PSKs.json file at c:ProgramDataRockwell AutomationFactoryTalk System ServicesPSKs.json and any backup copies with timestamped suffixes
- After upgrade, recreate security zones and conduits, then redeploy CIP Security policies
- For OPC UA deployments, ensure clients remove previously applied certificates and re-establish trust with new certificates
Evidence notes
The vulnerability affects FactoryTalk System Services v6.40 and FactoryTalk Policy Manager v6.40. The root cause is improper access control on private key storage locations, specifically the keystore folder and PSKs.json file within the FactoryTalk System Services directory structure. The vendor has released version 6.40.01 to address this issue. Remediation requires a multi-step process: clearing existing CIP Security configurations, deleting vulnerable key material and backups, updating to the patched version, and regenerating security policies.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-6325 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-6325
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-6325 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-6325
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-193-19.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-193-19
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.