CVE-2024-6242: Rockwell Automation 1756-EN2F
High severity, CVSS 7.3. EPSS: 11.1% chance of exploitation in the next 30 days.
A vulnerability exists in Rockwell Automation affected products that allows a threat actor to bypass the Trusted® Slot feature in a ControlLogix® controller. If exploited on any affected module in a 1756 chassis, a threat actor could potentially execute CIP commands that modify user projects and/or device configuration on a Logix controller in the chassis.
Affected products
- Rockwell Automation 1756-EN2F
- Rockwell Automation 1756-EN2T
- Rockwell Automation 1756-EN2TP
- Rockwell Automation 1756-EN2TR
- Rockwell Automation 1756-EN3TR
- Rockwell Automation 1756-EN4TR: version V2 only
- Rockwell Automation Controllogix 5580 1756-l8z: version V28 only
- Rockwell Automation Guardlogix 5580 1756-l8zs: version V31 only
Published 2024-08-01. Last modified 2026-06-17.