Rockwell Automation Fixes Flaws in Factory Software and Hardware

New security flaws in Rockwell Automation's industrial software and network hardware could let attackers disrupt factories or gain unauthorized access.

Rockwell Automation Fixes Flaws in Factory Software and Hardware

What happened

Federal cybersecurity officials have issued three separate warnings about security weaknesses in products made by Rockwell Automation, a major supplier of industrial control systems used in factories and manufacturing plants around the world. The flaws affect a piece of engineering software called Studio 5000 Logix Designer, a line of networking hardware known as the 1718-AENTR and 1719-AENTR, and a platform called FactoryTalk Services Platform that helps manage user access across industrial systems.

These are not products that ordinary people use at home. They run in the background at manufacturing facilities, helping control machinery, robotics, and production lines. But problems in this kind of equipment matter to everyday consumers too, because the same factories often produce goods, parts, and materials that end up in stores and homes.

The software flaw in Studio 5000 Logix Designer

Studio 5000 Logix Designer is used by engineers to program and configure the controllers that run factory equipment. Several versions of the software, spanning releases from V33 through V36, contain a flaw that could let someone with local access to a machine run unauthorized files, change system settings, or execute code they should not be able to run.

In practical terms, this means that if an attacker already has some level of access to a computer running this software, whether through a compromised account, a shared workstation, or physical access, they could potentially take actions well beyond what they should be allowed to do. Two additional related issues were identified specifically in version 35.00 of the software, adding to the list of problems that need patching.

A weak point in networking hardware

The second issue involves the 1718-AENTR and 1719-AENTR, which are network communication modules used to connect industrial equipment in hazardous or explosion-prone environments, such as chemical plants or oil and gas facilities. This flaw involves how the devices manage system resources. Without proper limits in place, an attacker could overwhelm the device with requests, causing it to stop working correctly. This is known as a denial-of-service condition, and it means the equipment could become unresponsive at a critical moment, potentially halting production or disrupting safety systems that depend on it.

Manufacturing counts as critical infrastructure, meaning problems in these systems are treated with the same seriousness as issues affecting power grids or water treatment plants. A network module going down unexpectedly is not just an inconvenience. It can stop an entire production line or create safety risks for workers nearby.

Weak authentication in FactoryTalk

The third flaw affects FactoryTalk Directory, part of the FactoryTalk Services Platform that companies use to manage who has access to what across their industrial systems. This one centers on weak authentication, meaning the way the system verifies a user's identity is not strong enough. An attacker who takes advantage of this weakness could pretend to be an authorized user on the server, potentially gaining access to sensitive configuration settings they should never be able to see or change.

This type of flaw is particularly concerning because authentication is supposed to be the gatekeeper. If someone can bypass it or trick it into thinking they are someone else, they can move through a system with a false sense of legitimacy, making their actions harder to detect and stop.

Why this matters beyond the factory floor

None of these three issues require a hacker to be a criminal mastermind working from across the globe. Two of them depend on some form of existing access, whether local to a machine or through a compromised account, while the third relies on overwhelming a device with traffic. That actually makes them more realistic threats, since insider mistakes, stolen credentials, and unpatched systems are far more common causes of industrial security incidents than sophisticated remote attacks.

Companies that rely on Rockwell Automation products are typically industrial operators, not individual consumers, so most readers will not need to take direct action on their own devices. But incidents like this are a reminder of how much everyday life depends on industrial systems that rarely make headlines until something goes wrong.

What you should do

  • If you work in manufacturing, industrial operations, or IT support for a company using Rockwell Automation equipment, check with your organization's security or engineering team to confirm whether patches or updates have been applied.
  • Keep all industrial software and firmware updated as soon as vendors release fixes, and avoid delaying updates on systems connected to production equipment.
  • Limit who has physical or remote access to engineering workstations, since several of these flaws depend on an attacker already having some level of access.
  • Review authentication settings on any platform managing user permissions across your systems, and consider adding extra verification steps where possible.
  • As a general consumer, there is no direct action needed, but staying aware of how industrial security issues can affect supply chains and manufacturing is a useful habit.