This release includes security enhancements as a part of our ongoing efforts to improve security. For information regarding Rockwell Automation's vulnerability disclosure process, please reference the Rockwell Automation Vulnerability Policy.
Denial-of-Service Vulnerability That Affects Logix 5000™ Controllers (1042476,1042479)
|
Controllers
|
First Known in Firmware
Revision
|
Corrected in Firmware
Revision
|
|
CompactLogix™ 5370
|
20.011
|
33.016, 34.011 and later
|
|
Compact GuardLogix®
5370
|
28.011
|
33.016, 34.011 and later
|
|
ControlLogix® 5570
|
20.011
|
33.016, 34.011 and later
|
|
ControlLogix 5570
redundant
|
20.054
|
33.053, 34.051 and later
|
|
GuardLogix 5570
|
20.011
|
33.016, 34.011 and later
|
|
CompactLogix 5380
|
28.011
|
32.016, 33.011 and later
|
|
Compact GuardLogix 5380
SIL 2
|
31.011
|
32.016, 33.011 and later
|
|
Compact GuardLogix 5380
SIL 3
|
32.013
|
32.016, 33.011 and later
|
|
CompactLogix 5480
|
32.011
|
32.016, 33.011 and later
|
|
ControlLogix 5580
|
28.011
|
32.016, 33.011 and later
|
|
GuardLogix 5580
|
31.011
|
32.016, 33.011 and later
|
For a full list of the potentially affected Rockwell Automation products and a description of the vulnerability, see Knowledgebase Product Notice Logix Controllers Vulnerable to Denial-of-Service Attack.
CVE-2022-3157: Denial-of-Service Vulnerability That Affects Logix 5000™ Controllers (1256258, 1289747)
|
Controllers
|
First Known in
Firmware
Revision
|
Corrected in Firmware
Revision
|
|
CompactLogix™ 5370
|
20.011
|
33.013, 34.011 and later
|
|
Compact GuardLogix® 5370
|
28.011
|
33.013, 34.011 and later
|
|
ControlLogix® 5570
|
20.011
|
33.013, 34.011 and later
|
|
GuardLogix 5570
|
20.011
|
33.013, 34.011 and later
|
|
ControlLogix 5570 redundant
|
20.054
|
33.052, 34.051 and later
|
For a full list of the potentially affected Rockwell Automation products and a description of the vulnerability, see Knowledgebase Product Notice Controllers Vulnerable to a Denial-of-Service Vulnerability.
CVE-2020-6998: Denial-of-Service Vulnerability That Affects Logix 5000™ Controllers (00228528)
|
Controllers
|
First Known in
Firmware Revision
|
Corrected in
Firmware Revision
|
|
CompactLogix™ 5370
|
20.011
|
33.011 and later
|
|
Compact GuardLogix® 5370
|
28.011
|
33.011 and later
|
|
ControlLogix® 5570
|
20.011
|
33.011 and later
|
|
GuardLogix 5570
|
20.011
|
33.011 and later
|
|
ControlLogix 5570 redundant
|
20.054
|
33.051 and later
|
For a full list of the potentially affected Rockwell Automation products and a description of the vulnerability, see Knowledgebase Product Notice CompactLogix 5370 and ControlLogix 5570 Controllers Vulnerable to Denial of Service Conditions due to Improper Input Validation.
This release has the following requirements.
Minimum Value for the Watchdog Time Revision 24
Catalog Numbers
To set the ControlLogix 5570 controllers initial task tuning, follow these steps.
IMPORTANT: This works only when there is no Continuous task configured in the Logix application.
Version of the Logix5000 Task Monitor v3.4.2.0
ControlLogix Redundancy Compatible Software 24.053_kit1
Catalog Numbers
|
Software
|
Required Software Version, Min
|
|
CompareTool
|
6.10.00.33
|
|
ControlFLASH™
|
14.01.00.01
|
|
FactoryTalk® Services Platform
|
2.90.00.172
|
|
FactoryTalk Activation
|
4.00.02.018
|
|
FactoryTalk Alarms and Events(1)
|
2.90.00.207
|
|
FactoryTalk AssetCentre
|
6.10.00.07 (CPR9-SR7)
|
|
FactoryTalk Batch
|
12.01.00(3)
|
|
FactoryTalk View Site Edition(2)
|
9.00.00.241
|
|
Logix5000™ Task Monitor
|
3.04.2.0
|
|
Redundancy Module Configuration Tool
|
8.4.1.0
|
|
RSLinx® Enterprise
|
5.90.00.187 (CPR9-SR7.1)
|
|
RSLinx Classic
|
3.90.00.24 (CPR9-SR7.1)
|
|
Studio 5000 Logix Designer®
|
24.01.00
|
|
RSNetWorx™ for ControlNet
|
26.00.00
|
|
RSNetWorx for EtherNet/IP
|
26.00.00
|
(1) You must download a FactoryTalk Alarm and Events patch in Rockwell Automation Knowledgebase Answer ID 730429. The patch is available at http://www.rockwellautomation.com/knowledgebase/.
(2) The installation of FactoryTalk View Site Edition also installs FactoryTalk Services Platform, which installs FactoryTalk Alarms and Events. Also, if you download and install the latest FactoryTalk Services Patch Rollup, this patch automatically installs the patch for FactoryTalk Alarms and Events.
(3) Use the most recent FactoryTalk Batch Patch Roll-up with this redundancy firmware revision. For the most recent patch roll-up, see Rockwell Automation Knowledgebase Answer ID 59058, accessible at: http://www.rockwellautomation.com/knowledgebase/.
IMPORTANT: The following steps apply only to the FactoryTalk Alarms and Events installation.
This installation installs FactoryTalk Services Platform, which installs FactoryTalk Alarms and Events.
This installation automatically installs the patch for FactoryTalk Alarms and Events.
ControlLogix Redundancy System Components 24.053_kit1
Catalog Numbers
|
Cat. No.
|
Module Description
|
Series
|
Firmware
Revision
|
|
1756-EN2T
|
ControlLogix EtherNet/IP
communication module
|
D
|
10.0102,3
|
|
C or earlier
|
5.008 or 5.0284,5
| ||
|
1756-EN2TR
|
ControlLogix EtherNet/IP
communication module
|
C
|
10.0103,6
|
|
B or earlier
|
5.008 or 5.0285,7
| ||
|
1756-EN2F
|
ControlLogix EtherNet/IP fiber
communication module
|
C
|
10.0108
|
|
B or earlier
|
5.008 or 5.0284,5
| ||
|
1756-EN2TXT
|
ControlLogix-XT™
EtherNet/IP communication
module
|
D
|
10.0102,3
|
|
C or earlier
|
5.008 or 5.0284,5
| ||
|
1756-EN2TRXT
|
ControlLogix-XT EtherNet/IP
communication module
|
C
|
10.0103,6
|
|
B
|
5.0285,7
| ||
|
1756-EN2TRK
|
ControlLogix EtherNet/IP
communication module
(conformal coated)
|
C
|
10.0103,6
|
|
1756-EN2TK
|
ControlLogix EtherNet/IP
communication module
(conformal coated)
|
D
|
10.0102,3
|
|
1756-CN2
|
ControlLogix ControlNet
bridge module
|
B
|
20.020
|
|
C
|
25.0051
| ||
|
1756-CN2R
|
ControlLogix redundant media
ControlNet bridge module
|
B
|
20.020
|
|
C
|
25.0051
| ||
|
1756-CN2RXT
|
ControlLogix-XT redundant
media ControlNet bridge
module
|
B
|
20.020
|
|
C
|
25.0051
| ||
|
1756-CN2RK
|
ControlLogix redundant
ControlNet bridge (conformal
coated) module
|
C
|
25.0051
|
|
1756-L71
1756-L72 1756-L73 1756-L73XT 1756-L74 1756-L75 |
ControlLogix 5570 controllers,
redundant
|
All
|
24.053
|
|
1756-RM2
|
ControlLogix redundancy
module
|
All
|
20.009
|
|
1756-RM2K
|
ControlLogix redundancy
module
|
All
|
20.009
|
|
1756-RM2XT
|
ControlLogix-XT redundancy
module
|
All
|
20.009
|
(1) IMPORTANT: The 1756-CN2/C, 1756-CN2R/C, 1756-CN2RXT/C, 1756-CN2RK/C modules do not support firmware revisions previous to revision 25.004.
(2) IMPORTANT: The 1756-EN2T/D modules do not support firmware revisions previous to revision 10.006.
(3) Firmware revision 10.006 or later is digitally signed.
(4) IMPORTANT: The 1756-EN2T/C (or earlier) modules do not support firmware revision 10.006 or later.
(5) Firmware revision 5.028 is digitally signed firmware. Firmware revision 5.008 is unsigned firmware.
(6) IMPORTANT: The 1756-EN2TR/C modules do not support firmware revisions previous to revision 10.007.
(7) IMPORTANT: The 1756-EN2TR/B (or earlier) modules do not support firmware revision 10.007.
(8) IMPORTANT: The 1756-EN2F/C modules do not support firmware revisions before revision 10.009.
For more information on how to update your ControlLogix® redundancy system, see Replacement Guidelines: Update ControlLogix Redundancy Reference Manual, publication 1756-RM010.
For more information on how to install, configure and use your ControlLogix redundancy system, see the ControlLogix Redundancy User Manual, publication 1756-UM535.
Known Restrictions as of ControlLogix® Redundancy Revision 24.053_kit1
This revision provides support for the following:
Catalog Numbers
ControlLogix System User Manual, publication 1756-UM001
Integrated Architecture® and CIP Sync Configuration Application Technique, publication IA-AT003
Consider the following when you use CIP Sync technology in a redundancy system:
Digitally Signed Ethernet Module Firmware for Revision 24.053_kit1
Catalog Numbers
Digitally signed firmware provides more security over the unsigned firmware. This firmware is different based on the EtherNet/IP communication modules you use.
|
Cat. No.
|
Supported Firmware
Revisions
|
Digitally Signed
Firmware
|
Included with this
Redundancy Bundle
|
|
1756-EN2T/D
|
10.010 or later
|
Yes
|
Yes
|
|
1756-EN2T/C or
earlier
|
5.008
|
No
|
Yes
|
|
5.028
|
Yes
|
No
| |
|
1756-EN2TR/C
|
10.010 or later
|
Yes
|
Yes
|
|
1756-EN2TR/B or
earlier
|
5.008
|
No
|
Yes
|
|
5.028
|
Yes
|
No
| |
|
1756-EN2F/C
|
10.010 or later
|
Yes
|
Yes
|
|
1756-EN2F/B or
earlier
|
5.008
|
No
|
Yes
|
|
5.028
|
Yes
|
No
|
Firmware revision 5.028 is not included in the redundancy system, revision 24.053_kit1 firmware bundle. You must download and install this digitally signed firmware after the redundancy bundle is installed.
Important: When you install the digitally signed firmware, that is, firmware revision 5.028, into a 1756-EN2T/C (or earlier), 1756-EN2TR/B (or earlier), or 1756-EN2F/B (or earlier) module, the installation makes the module incompatible with some firmware revisions. For example, after you update firmware, the module supports use of only digitally signed firmware. The module rejects any unsigned firmware updates.
|
From Firmware Revision
|
Firmware Revision Updates Conditionally Not Allowed*
|
|
20.058_kit3
|
24.052_kit1, 24.053_kit1
|
|
24.052_kit1
|
—
|
|
24.053_kit1
|
—
|
|
24.053_kit2
|
30.051_kit1, 30.051_kit2, 30.051_kit3
|
|
30.051_kit1
|
—
|
|
30.051_kit2
|
31.052_kit1, 31.052_kit2
|
|
30.051_kit3
|
31.052_kit1, 31.052_kit2, 31.052_kit3
|
|
30.051_kit4
|
31.052_kit1, 31.052_kit2, 31.052_kit3, 31.052_kit4
|
|
31.052_kit1
|
—
|
|
31.052_kit2
|
32.051_kit1
|
|
31.052_kit3
|
32.051_kit1
|
|
31.052_kit4
|
32.051_kit1, 32.051_kit2
|
|
31.052_kit5
|
32.051_kit1, 32.051_kit2, 32.051_kit3
|
|
32.051_kit1
|
—
|
|
32.051_kit2
|
33.051_kit1
|
|
32.051_kit3
|
33.051_kit1, 33.051_kit2, 33.052_kit1
|
|
32.051_kit4
|
33.051_kit1, 33.051_kit2, 33.052_kit1, 33.053_kit1
|
|
33.051_kit1
|
—
|
|
33.051_kit2
|
—
|
|
33.052_kit1
|
—
|
|
33.053_kit1
|
34.051_kit1
|
|
33.053_kit2
|
34.051_kit1, 34.052_kit
|
|
34.051_kit1
|
—
|
|
34.052_kit1
|
35.051_kit1
|
|
34.053_kit1
|
35.051_kit1, 35.052_kit1
|
|
35.051_kit1
|
—
|
|
35.052_kit1
|
—
|
|
35.053_kit1
|
36.051_kit1
|
|
36.051_kit1
|
—
|
|
36.052_kit1
|
37.051_kit1
|
|
37.051_kit1
|
—
|
|
37.051_kit2
|
—
|
|
38.051_kit1
|
—
|
This release includes the following system features.
Catalog Numbers
IMPORTANT: You must uninstall any existing versions of the Redundancy Module Configuration Tool (RMCT) before you install version 8.4.1.0 of the RMCT. If you do not uninstall the previous versions, you can have difficulty if you try to uninstall version 8.4.1.0 later.
You can use 1756-RM2 or 1756-RM2XT redundancy modules to commission a redundant system. You can commission a system without any additional programming. However, there is additional functionality available if you use the modules with the RMCT.
This release corrects the following anomalies.
Dynamix 1444 Reconfiguration Error when Modifying Configuration Online (Lgx00178261)
Corrected: Studio 5000 Logix Designer® Version 24.053_kit1
Catalog Numbers: Dynamix™ 1444
Corrected Anomaly in Firmware Revisions 24.053 and 30.051
Catalog Numbers: ControlLogix® 5570 Redundant Controllers
Known Anomaly first identified as of firmware revision 20.054
New Primary Controller Experiences a T04:C82 SFC Jump Back Failure (Lgx00187293 and Lgx00187316)
Corrected Anomaly with Firmware Revisions 24.053 and 30.051
Known Anomaly First Identified as of Firmware Revision 24.052
Catalog Numbers: ControlLogix® 5570 Redundant Controllers
After a switchover, the new primary chassis controller experiences a Major Fault Type 4 Code 82 (T04:C82) SFC Jump Back Fault. This can occur in a redundant system when SFC’s are in a continuous task in the user’s application.
For information, see Knowledgebase Article ControlLogix Redundancy New Primary Experiences a T04:C82 SFC Jump Back Major Recoverable Fault
Small Timing Window when Crossloading the Key Switch and Controller (Lgx00185375)
Corrected: Studio 5000 Logix Designer® Version 24.053_kit1
Catalog Numbers:
There is a small timing window when crossloading the key switch and controller mode information to the secondary controller during qualification that can result in the primary controller MNRFing (major non-recoverable fault). This condition has the potential to occur if there are User periodic tasks that take longer than 200 milliseconds to execute. When this condition occurs, it results in the primary controller that is MNRFed and secondary controller that could not take control since it was not synchronized.
See Rockwell Automation Knowledgebase Answer ID 943413, accessible at:
http://www.rockwellautomation.com/knowledgebase/ (log on is required).
|
Controllers
|
First Known in
Firmware Revision
|
Corrected in Firmware
Revision
|
|
ControlLogix® 5570 Redundant
|
19.052
|
20.054 and later
|
|
ControlLogix 5060 Redundant
|
19.052
|
20.054 and later
|
This release has the following known anomalies.
Applications with PowerFlex drives in the I/O configuration can experience a major non-recoverable fault (MNRF) (00200734, 00200735, 00200600, 00200599)
Corrected Anomaly as of Firmware Revision 31.011 and 30.014 for these catalog numbers:
Corrected Anomaly as of Firmware Revision 31.011 and 30.013 for these catalog numbers:
Known Anomaly First Identified as of Firmware Revision 28.011 for these catalog numbers:
Known Anomaly First Identified as of Firmware Revision 20.011 for these catalog numbers:
If a controller already has an application loaded into it that contains PowerFlex drives in the I/O configuration, a MNRF (Major Non-Recoverable Fault) can occur when any of the following occurs:
For more information and workarounds, see Knowledgebase document 1067997.
These anomalies are from previous releases but are still known in this release.
Some Faults Are Not Logged in The Controller Log (1061142, 1594647)
|
Controllers
|
First Known in Firmware
Revision
|
Corrected in Firmware
Revision
|
|
CompactLogix™ 5370
|
20.011
|
33.016, 34.011 and later
|
|
Compact GuardLogix® 5370
|
28.011
|
33.016, 34.011 and later
|
|
ControlLogix® 5570
|
20.011
|
33.016, 34.011 and later
|
|
ControlLogix 5570 redundant
|
20.054
|
33.053, 34.051 and later
|
|
GuardLogix 5570
|
20.011
|
33.016, 34.011 and later
|
The Controller Log feature does not properly log User Task Watchdog faults (Type 6 Code 1) in the Controller Log. For more information about the Controller Log feature, see the Logix 5000® Controllers Information and Status Programming Manual, publication 1756-PM015.
PCMD Returns Incorrect Error Code (1056295)
|
Controllers
|
First Known in Firmware
Revision
|
Corrected in Firmware
Revision
|
|
CompactLogix™ 5370
|
20.011
|
34.011
|
|
Compact GuardLogix® 5370
|
28.011
|
34.011
|
|
ControlLogix® 5570
|
20.011
|
34.011
|
|
ControlLogix 5570 redundant
|
20.054
|
34.051
|
|
GuardLogix 5570
|
28.011
|
34.011
|
|
CompactLogix 5380
|
28.011
|
34.011
|
|
Compact GuardLogix 5380 SIL 2
|
31.011
|
34.011
|
|
Compact GuardLogix 5380 SIL 3
|
32.013
|
34.011
|
|
CompactLogix 5380 Process
|
33.011
|
34.011
|
|
CompactLogix 5480
|
32.011
|
34.011
|
|
ControlLogix 5580
|
28.011
|
34.011
|
|
GuardLogix 5580
|
31.011
|
34.011
|
|
ControlLogix 5580 Process
|
33.011
|
34.011
|
Equipment Phase Command (PCMD) returns the incorrect error code “0x6003, HIGH_PRIORITY_OWNED” when it should return “0x6004, NOT_ATTACHED”
Controller Can Assert During The I/O Module Configuration Process (1024030, 00219969)
|
Controllers
|
First Known in Firmware
Revision
|
Corrected in Firmware
Revision
|
|
CompactLogix™ 5370
|
20.011
|
34.011
|
|
Compact GuardLogix® 5370
|
28.011
|
34.011
|
|
ControlLogix® 5570
|
20.011
|
34.011
|
|
ControlLogix 5570 redundant
|
20.054
|
34.051
|
|
GuardLogix 5570
|
28.011
|
34.011
|
|
CompactLogix 5380
|
28.011
|
33.011
|
|
Compact GuardLogix 5380 SIL 2
|
31.011
|
33.011
|
|
Compact GuardLogix 5380 SIL 3
|
32.013
|
33.011
|
|
CompactLogix 5480
|
32.011
|
33.011
|
|
ControlLogix 5580
|
28.011
|
33.011
|
|
GuardLogix 5580
|
31.011
|
33.011
|
Certain I/O modules send more configuration data than fits in a standard forward open (508 bytes) when the connection is being established. Therefore, the configuration process can take longer to complete. Examples include E300™ Electronic Overload Relays, 1444 Dynamics, 1718 I/O, 1719 I/O, and many third-party I/O devices.
When the configuration data is being sent to the device, if you change the configuration through the Add-on Profile for the device and then apply the changes the controller can assert.
Grandmaster Clock Description Not Correctly Being Displayed (939979)
|
Controllers
|
First Known in Firmware
Revision
|
Corrected in Firmware
Revision
|
|
CompactLogix™ 5370
|
20.011
|
34.011
|
|
Compact GuardLogix® 5370
|
28.011
|
34.011
|
|
ControlLogix® 5570
|
20.011
|
34.011
|
|
ControlLogix 5570 redundant
|
20.054
|
34.051
|
|
GuardLogix 5570
|
20.011
|
34.011
|
Located in controller properties → Date Time → Advanced → Grandmaster Clock description could be shown as a blank description or could be showing old information. This does not impact time synchronization.
This release has the following functional changes from the previous release.
This release has the following application notes.
Communication Interruption on EtherNet/IP Networks for Revision 24.053_kit1
Application Notes
Catalog Numbers
These connection types can experience the communication delay when a switchover occurs:
IMPORTANT: The Batch Server detects the lost connection and repeatedly attempts to
reestablish the connection until successful. However, while the connection is lost, the
Batch Server puts the recipes, or entire batch, in the held state.
After the connection between the Batch Server and the redundant chassis pair is
reestablished, you can clear the communication failure and restart the recipes. The
Batch Server keeps the recipes in the held state until the failure is cleared and recipes
restarted.
If any alarms are generated while the connection is lost, that data is buffered. When the connection is reestablished, you must acknowledge the connection loss.
If your application requires that the connections described above are maintained during a switchover, we recommend the following:
IMPORTANT: I/O connections do not experience delays when a switchover occurs.
Use these firmware revisions for EtherNet/IP communication modules in the remote chassis to maintain I/O and Produce/Consume connections during a switchover.
|
EtherNet/IP Communication Module in Remote Chassis
|
Minimum Firmware
Revision
|
|
1756-EN2F
|
5.008 (unsigned)
5.028 (signed)
|
|
1756-EN2T
|
4.002
|
|
1756-EN2TR
| |
|
1756-EN3TR
| |
|
1756-ENBT
|
6.005
|
|
1768-ENBT
|
4.001
|
|
1769-L2x
|
19.011
|
|
1769-L3xE
| |
|
1788-ENBT
|
3.001
|
Synchronize after Disqualification for Revision 24.053_kit1
Application Notes
Catalog Numbers
If your secondary chassis becomes disqualified, or you manually disqualify it, perform these actions before you try to synchronize the chassis.
Increase Product Resiliency for Revision 24.053_kit1
Application Notes
Catalog Numbers