PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-8533 Rockwell Automation CVE debrief

A privilege escalation vulnerability in Rockwell Automation OptixPanel products allows credential exfiltration through improper default file permissions. The vulnerability affects three product lines: 2800C OptixPanel Compact (version 4.0.0.325), 2800S OptixPanel Standard (version 4.0.0.350), and Embedded Edge Compute Module (version 4.0.0.347). The issue was disclosed on September 12, 2024, with a CVSS 3.1 score of 7.5 (HIGH). Rockwell Automation has released patched versions: 4.0.2.116 for the Compact model, 4.0.2.123 for the Standard model, and 4.0.2.106 for the Embedded Edge Compute Module. The vulnerability requires network access and user interaction, with high attack complexity, but successful exploitation results in complete compromise of confidentiality, integrity, and availability.

Vendor
Rockwell Automation
Product
2800C OptixPanel Compact
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-09-12
Original CVE updated
2024-09-12
Advisory published
2024-09-12
Advisory updated
2024-09-12

Who should care

Organizations operating Rockwell Automation OptixPanel HMI devices in industrial environments, particularly manufacturing, energy, and critical infrastructure sectors. Security teams responsible for OT/ICS asset management and patch deployment should prioritize this vulnerability due to the credential exfiltration risk and potential for lateral movement in industrial networks.

Technical summary

The vulnerability stems from improper default file permissions on affected Rockwell Automation OptixPanel systems, allowing authenticated or local users to access sensitive credential files. The CVSS 3.1 vector (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H) indicates network accessibility with high attack complexity, no privileges required, and user interaction needed. Successful exploitation enables complete system compromise. The attack surface is reduced by the high complexity requirement and need for user interaction, but the impact is severe given the high-value target environment of industrial control systems.

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade affected Rockwell Automation OptixPanel products to patched versions: 2800C OptixPanel Compact to 4.0.2.116, 2800S OptixPanel Standard to 4.0.2.123, or Embedded Edge Compute Module to 4.0.2.106
  • Review and harden file permissions on OptixPanel systems to prevent unauthorized credential access
  • Implement network segmentation for industrial control systems to limit exposure of OptixPanel devices
  • Apply Rockwell Automation's security best practices for industrial automation control systems
  • Monitor for anomalous access patterns to credential storage locations on affected systems

Evidence notes

Source: CISA CSAF advisory ICSA-24-256-19. CVSS vector confirms network attack vector with high attack complexity requiring user interaction. Three specific product versions identified with corresponding vendor fixes.

Official resources

2024-09-12