CVE-2024-7847

Severity CVSS v4.0:
HIGH
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
14/10/2024
Last modified:
29/09/2025

Description

VULNERABILITY DETAILS<br /> <br /> Rockwell Automation used the latest versions of the CVSS scoring system to assess the following vulnerabilities. The following vulnerabilities were reported to us by Sharon Brizinov of Claroty Research - Team82. <br /> <br /> A feature in the affected products enables users to prepare a project file with an embedded VBA script and can be configured to run once the project file has been opened without user intervention. This feature can be abused to trick a legitimate user into executing malicious code upon opening an infected RSP/RSS project file. If exploited, a threat actor may be able to perform a remote code execution. Connected devices may also be impacted by exploitation of this vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rockwellautomation:rslogix_5:-:*:*:*:*:*:*:*
cpe:2.3:a:rockwellautomation:rslogix_500:-:*:*:*:*:*:*:*
cpe:2.3:a:rockwellautomation:rslogix_micro_developer:-:*:*:*:*:*:*:*
cpe:2.3:a:rockwellautomation:rslogix_micro_starter_lite:-:*:*:*:*:*:*:*