CVE-2024-7847
VULNERABILITY DETAILS
Rockwell Automation used the latest versions of the CVSS scoring system to assess the following vulnerabilities. The following vulnerabilities were reported to us by Sharon Brizinov of Claroty Research - Team82.
A feature in the affected products enables users to prepare a project file with an embedded VBA script and can be configured to run once the project file has been opened without user intervention. This feature can be abused to trick a legitimate user into executing malicious code upon opening an infected RSP/RSS project file. If exploited, a threat actor may be able to perform a remote code execution. Connected devices may also be impacted by exploitation of this vulnerability.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 7
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1203Exploitation for Client Executionexecution90 % - Impacto principal
T1059Command and Scripting Interpreterexecution85 % - Impacto secundario
T1195.002Compromise Software Supply Chaininitial access75 %
Vector AV:L + UI:P + ejecución de VBA incrustado al abrir archivo RSP/RSS preparado = explotación en cliente (T1203). El impacto principal es ejecución de código arbitrario (T1059); secundariamente, el archivo manipulado representa cadena de suministro (T1195.002).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (4)
CWE
- CWE-345
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-7847",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-7847",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-10-14T15:18:18.670939Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "PSIRT@rockwellautomation.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 7.7,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 1
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "PSIRT@rockwellautomation.com",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 8.8,
"Automatable": "NOT_DEFINED",
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "PASSIVE",
"attackComplexity": "HIGH",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "HIGH",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "PSIRT@rockwellautomation.com",
"affectedData": [
{
"vendor": "Rockwell Automation",
"product": "RSLogix 500®",
"versions": [
{
"status": "affected",
"version": "All"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Rockwell Automation",
"product": "RSLogix™ Micro Developer and Starter",
"versions": [
{
"status": "affected",
"version": "All"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Rockwell Automation",
"product": "RSLogix™ 5",
"versions": [
{
"status": "affected",
"version": "All"
}
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:rockwellautomation:rslogix_500:*:*:*:*:*:*:*:*"
],
"vendor": "rockwellautomation",
"product": "rslogix_500",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:rockwellautomation:rslogix_micro_developer:*:*:*:*:*:*:*:*"
],
"vendor": "rockwellautomation",
"product": "rslogix_micro_developer",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:rockwellautomation:rslogix_micro_starter:*:*:*:*:*:*:*:*"
],
"vendor": "rockwellautomation",
"product": "rslogix_micro_starter",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:rockwellautomation:rslogix_5:*:*:*:*:*:*:*:*"
],
"vendor": "rockwellautomation",
"product": "rslogix_5",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-10-14T14:15:12.020",
"references": [
{
"url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1701.html",
"tags": [
"Vendor Advisory"
],
"source": "PSIRT@rockwellautomation.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "PSIRT@rockwellautomation.com",
"description": [
{
"lang": "en",
"value": "CWE-345"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "VULNERABILITY DETAILS\n\nRockwell Automation used the latest versions of the CVSS scoring system to assess the following vulnerabilities. The following vulnerabilities were reported to us by Sharon Brizinov of Claroty Research - Team82. \n\nA feature in the affected products enables users to prepare a project file with an embedded VBA script and can be configured to run once the project file has been opened without user intervention. This feature can be abused to trick a legitimate user into executing malicious code upon opening an infected RSP/RSS project file. If exploited, a threat actor may be able to perform a remote code execution. Connected devices may also be impacted by exploitation of this vulnerability."
},
{
"lang": "es",
"value": "DETALLES DE LA VULNERABILIDAD Rockwell Automation utilizó las últimas versiones del sistema de puntuación CVSS para evaluar las siguientes vulnerabilidades. Sharon Brizinov de Claroty Research - Team82 nos informó sobre las siguientes vulnerabilidades. Una característica de los productos afectados permite a los usuarios preparar un archivo de proyecto con un script VBA integrado y se puede configurar para que se ejecute una vez que se haya abierto el archivo de proyecto sin intervención del usuario. Esta característica se puede utilizar de forma abusiva para engañar a un usuario legítimo para que ejecute código malicioso al abrir un archivo de proyecto RSP/RSS infectado. Si se explota, un actor de amenazas puede realizar una ejecución remota de código. Los dispositivos conectados también pueden verse afectados por la explotación de esta vulnerabilidad."
}
],
"lastModified": "2026-06-17T08:21:02.193",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:rockwellautomation:rslogix_5:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A7F1B90D-82A6-47BA-AF26-46F57397677A"
},
{
"criteria": "cpe:2.3:a:rockwellautomation:rslogix_500:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A61D6933-397E-40BC-83A9-8581352AE43B"
},
{
"criteria": "cpe:2.3:a:rockwellautomation:rslogix_micro_developer:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CF938B05-B208-45DA-BE12-B3C2DDD2CD00"
},
{
"criteria": "cpe:2.3:a:rockwellautomation:rslogix_micro_starter_lite:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E7607CF5-A97A-4879-8668-4EC4BA2343D7"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "PSIRT@rockwellautomation.com"
}