Rockwell Automation Redundancy Module Configuration Tool
Plan PatchCVSS 7.3ICS-CERT ICSA-26-244-02Sep 1, 2026
Rockwell Automation
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionRequired
Summary
Rockwell Automation Redundancy Module Configuration Tool versions 9.00.00 through 10.00.00 contain privilege escalation vulnerabilities (CWE-276) that allow a local user to execute processes with administrator privileges. The tool is used to configure and manage redundancy settings for Rockwell PLC systems. Rockwell Automation has released version 10.01.00 as the corrected version.
What this means
What could happen
An attacker with local access to a machine running the Redundancy Module Configuration Tool could escalate privileges and run commands as an administrator, potentially allowing them to modify redundancy settings, disable failover protection, or compromise PLC configurations.
Who's at risk
Water utilities and electric utilities using Rockwell Automation Redundancy Module Configuration Tool on engineering workstations for managing redundant PLC systems and failover configuration. This affects any facility that relies on redundant controllers for continuous operation or safety-critical processes.
How it could be exploited
An attacker with a local user account on the engineering workstation running the Configuration Tool interacts with the tool through the user interface, triggering a privilege escalation vulnerability that grants administrator-level command execution on that machine.
Prerequisites
- Local user account on the engineering workstation running Redundancy Module Configuration Tool
- User interaction required (opening or interacting with the tool)
- Vulnerability present in versions 9.00.00 through 10.00.00
Low complexity exploitationUser interaction requiredLocal access onlyAffects device configuration tools
Exploitability
Unlikely to be exploited — EPSS score 0.1%
Affected products (3)
3 with fix
ProductAffected VersionsFix Status
Redundancy Module Configuration Tool: 10.00.0010.00.00Fix available
Redundancy Module Configuration Tool: >=9.00.00|<=10.00.00≥ 9.00.00|≤ 10.00.00Fix available
Redundancy Module Configuration ToolAll versions10.01.00
Remediation & Mitigation
0/4
Do now
0/2HARDENINGRestrict local login access to engineering workstations to authorized personnel only
WORKAROUNDReview Rockwell Automation security best practices at https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US for compensating controls pending upgrade
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Redundancy Module Configuration Tool
HOTFIXUpdate Redundancy Module Configuration Tool to version 10.01.00 or later
Long-term hardening
0/1HARDENINGImplement application whitelisting or execution controls on workstations running the Configuration Tool
CVEs (2)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/38035ace-8de4-4cab-bf4f-6e3fe8ae3962Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.