CVE-2024-6242 - CVE House
Back to Database
Status published High CVE-2024-6242

Rockwell Automation Chassis Restrictions Bypass Vulnerability in Select Logix Devices

Vulnerability Description

A vulnerability exists in Rockwell Automation affected products that allows a threat actor to bypass the Trusted® Slot feature in a ControlLogix® controller. If exploited on any affected module in a 1756 chassis, a threat actor could potentially execute CIP commands that modify user projects and/or device configuration on a Logix controller in the chassis.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-6242

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Claroty reported this vulnerability.

Affected Vendor

Rockwell Automation

View all reports →

Affected Software

ControlLogix® 5580 (1756-L8z), GuardLogix® 5580 (1756-L8zS), 1756-EN4TR, 1756-EN2T, 1756-EN2F, 1756-EN2TR, 1756-EN3TR, 1756-EN2TP
Vulnerable Versions:
V28, V31, V2, v5.007(unsigned)/v5.027(signed), 1756-EN2T/D: V10.006, 1756-EN2F/C: V10.009, 1756-EN2TR/C: V10.007, 1756-EN3TR/B: V10.007, 1756-EN2TP/A: V10.020

Timeline

Official Publish: August 1st, 2024
Last Modified: September 25th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.