CVE-2024-6242Active Exploitation

LOWCVSS 7.3 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability exists in Rockwell Automation affected products that allows a threat actor to bypass the Trusted® Slot feature in a ControlLogix® controller. If exploited on any affected module in a 1756 chassis, a threat actor could potentially execute CIP commands that modify user projects and/or device configuration on a Logix controller in the chassis.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-420

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Peaked 1d ago at 1 mentions (2026-04-15); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-15: 1Mentions · 2026-10-08: 1Active Exploitation · 2026-04-15: 104-1510-08
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets2 URLs
Full discourse2 posts
  • SHELLCODE@sh3ll_c0d3

    🏭 ROCKWELL CONTROLLOGIX CIP BYPASS! Flaw in Rockwell ControlLogix PLCs (CVE-2024-6242) lets attackers bypass CIP authorization to tamper with factory logic. 👉 Full analysis: https://sh3llc0d3.com/blog/rockwell-automation-controllogix-guardlogix-cip-vulnerabilities-dissecting-cve-2024-6242-and-trusted-slot-bypass/ #sh3llc0d3 #shellcode #ICS #OTSecurity #Rockwell

    0000038
    117 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Active Exploitation

    🔒 #CyberSecurity CVE-2024-6242: Rockwell Automation PLC Exploitation — Detection and Remediation… "Recent intelligence confirms that Iranian state-sponsored actors (specifically…" 🔗 https://securityarsenal.com/blog/cve-2024-6242-rockwell-automation-plc-exploitation-detection-and-remediation-guide #CyberSecurity #ThreatIntel #alertfatigue #triage #alertmonitor

    Post summary

    The text indicates that Iranian state-sponsored actors are actively exploiting CVE-2024-6242, but it provides no Proof of Concept, exploit code, patch, or detailed vulnerability information.

    0000038
    10 followersView on X

Explore more