{"api_version":"v1","generated_at":"2026-10-09T19:50:00+00:00","product":{"cve_count":3,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-rockwell-automation-isagraf-workbench-a97f45175127","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"ISaGRAF Workbench","next_cursor":null,"observations":[{"affected":"6.0 \u2264 6.6.9","affected_versions_present":true,"cve_id":"CVE-2022-2465","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-2465","fixed":"Version C3414-500-S02K5_P5 of SAGE RTU CPU 3414 includes a mitigation for these vulnerabilities and is available for download here: https://www.sage-rtu.com/downloads.html Reboot of SAGE RTU is required after firmware upgrade. This mitigation disables the ISaGRAF listening TCP ports by default and provides an additional network service checkbox to allow customers to enable the ISaGRAF ETCP task, which will open the TCP listening ports to connect with ISaGRAF workbench when needed, and to disable the TCP listening ports when ISaGRAF Workbench development, debugging, and downloading tasks are complete. These vulnerabilities can only be exploited when users reopen the listening ports and connect with ISaGRAF workbench. These vulnerabilities only apply when a non-secure network is being used to perform development tasks in non-runtime applications. It is our recommendation to mitigate these vulnerabilities by performing all ISaGRAF workbench tasks on a secure network or on a private network when connecting to the device. OR If firmware is not upgraded to C3414-500-S02K5_P5, but customers are running firmware version C3414-500-S02K2 or above, then they should immediately apply the following mitigations to reduce the risk of exploit: If ISaGRAF is configured and in use, the built-in firewall can be used to disable ISaGRAF port 1131 and 1113 when the debugger is not in use. Use the following commands in the Firewall configuration to disable external access to ISaGRAF: Block in proto tcp from any to any port = 1131 Block in proto tcp from any to any port = 1113 If ISaGRAF is NOT configured and in use, the ISaGRAF port is by default not enabled and does not start automatically, therefore there is no impact of these vulnerabilities, and no further action is required by customers.","last_modified":"2025-04-16T17:49:53.570Z","patch_url":"https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-284-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-284-03-SAGE_RTU_ISaGraf_Workbench_Security_Notification.pdf","primary_source":"","published":"2022-08-25T17:25:07.000Z"},{"affected":"6.0 \u2264 6.6.9","affected_versions_present":true,"cve_id":"CVE-2022-2464","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-2464","fixed":"Version C3414-500-S02K5_P5 of SAGE RTU CPU 3414 includes a mitigation for these vulnerabilities and is available for download here: https://www.sage-rtu.com/downloads.html Reboot of SAGE RTU is required after firmware upgrade. This mitigation disables the ISaGRAF listening TCP ports by default and provides an additional network service checkbox to allow customers to enable the ISaGRAF ETCP task, which will open the TCP listening ports to connect with ISaGRAF workbench when needed, and to disable the TCP listening ports when ISaGRAF Workbench development, debugging, and downloading tasks are complete. These vulnerabilities can only be exploited when users reopen the listening ports and connect with ISaGRAF workbench. These vulnerabilities only apply when a non-secure network is being used to perform development tasks in non-runtime applications. It is our recommendation to mitigate these vulnerabilities by performing all ISaGRAF workbench tasks on a secure network or on a private network when connecting to the device. OR If firmware is not upgraded to C3414-500-S02K5_P5, but customers are running firmware version C3414-500-S02K2 or above, then they should immediately apply the following mitigations to reduce the risk of exploit: If ISaGRAF is configured and in use, the built-in firewall can be used to disable ISaGRAF port 1131 and 1113 when the debugger is not in use. Use the following commands in the Firewall configuration to disable external access to ISaGRAF: Block in proto tcp from any to any port = 1131 Block in proto tcp from any to any port = 1113 If ISaGRAF is NOT configured and in use, the ISaGRAF port is by default not enabled and does not start automatically, therefore there is no impact of these vulnerabilities, and no further action is required by customers.","last_modified":"2025-04-16T17:50:01.212Z","patch_url":"https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-284-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-284-03-SAGE_RTU_ISaGraf_Workbench_Security_Notification.pdf","primary_source":"","published":"2022-08-25T17:24:59.000Z"},{"affected":"6.0 \u2264 6.6.9","affected_versions_present":true,"cve_id":"CVE-2022-2463","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-2463","fixed":"Version C3414-500-S02K5_P5 of SAGE RTU CPU 3414 includes a mitigation for these vulnerabilities and is available for download here: https://www.sage-rtu.com/downloads.html Reboot of SAGE RTU is required after firmware upgrade. This mitigation disables the ISaGRAF listening TCP ports by default and provides an additional network service checkbox to allow customers to enable the ISaGRAF ETCP task, which will open the TCP listening ports to connect with ISaGRAF workbench when needed, and to disable the TCP listening ports when ISaGRAF Workbench development, debugging, and downloading tasks are complete. These vulnerabilities can only be exploited when users reopen the listening ports and connect with ISaGRAF workbench. These vulnerabilities only apply when a non-secure network is being used to perform development tasks in non-runtime applications. It is our recommendation to mitigate these vulnerabilities by performing all ISaGRAF workbench tasks on a secure network or on a private network when connecting to the device. OR If firmware is not upgraded to C3414-500-S02K5_P5, but customers are running firmware version C3414-500-S02K2 or above, then they should immediately apply the following mitigations to reduce the risk of exploit: If ISaGRAF is configured and in use, the built-in firewall can be used to disable ISaGRAF port 1131 and 1113 when the debugger is not in use. Use the following commands in the Firewall configuration to disable external access to ISaGRAF: Block in proto tcp from any to any port = 1131 Block in proto tcp from any to any port = 1113 If ISaGRAF is NOT configured and in use, the ISaGRAF port is by default not enabled and does not start automatically, therefore there is no impact of these vulnerabilities, and no further action is required by customers.","last_modified":"2025-04-16T16:11:52.314Z","patch_url":"https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-284-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-284-03-SAGE_RTU_ISaGraf_Workbench_Security_Notification.pdf","primary_source":"","published":"2022-08-25T17:24:53.000Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"Rockwell Automation"}}
