Horizon Alert
Summary of the vulnerability and why it matters
This advisory addresses critical security flaws in Rockwell Automation's NAT devices, stemming from inadequate authentication checks on essential functions. These vulnerabilities could potentially lead to service disruptions, unauthorized administrative control, or manipulation of network routing rules, impacting device communication and potentially rerouting traffic to unintended destinations.
- Missing checks allow unauthorized control.
- Could disrupt network communications or take over devices.
- Confirm if your network routing technology is affected.
Attack Path
How an attacker could exploit the issue
An attacker could reach this device over the network without any authentication or special privileges. By targeting critical functions that lack proper authorization checks, they could disrupt network operations. This could lead to devices being unable to communicate, sending traffic to incorrect destinations, or a complete compromise of administrative control requiring physical intervention to fix.
- No authentication or network access required.
- Call unprotected critical functions.
- Denial of service or account takeover.
Live Threat
Current exploitation, exposure, and threat context
Multiple broken authentication vulnerabilities exist in the affected product due to missing checks on critical functions. These weaknesses could allow an attacker to disrupt device communication, redirect traffic to unintended endpoints, or take over an administrator account, potentially requiring physical access to recover. When supported by the advisory, affected devices could experience denial-of-service, leading to an inability to communicate through NATR, or NAT rule modifications that could reroute traffic to incorrect endpoints.
- Network traffic routing and control.
- Unauthorized function access by attackers.
- Service disruption and configuration compromise.
Operational Fix
Recommended remediation, mitigation, and detection steps
The affected NAT devices require immediate attention from infrastructure and security teams to mitigate significant risks. Given the potential for denial-of-service, administrator account takeover, or unauthorized NAT rule modifications, the first practical step is to identify all instances of this technology, confirm their network exposure and business criticality, and then assign ownership for remediation planning.
- Infrastructure and security teams own the issue.
- Verify device reachability and criticality first.
- Plan and coordinate remediation efforts.