Back

MEDIUM

ICSA-22-188-01 Rockwell Automation MicroLogix Improper Restriction of Rendered UI Layers or Frames

Published Jul 20, 2022

Description

The X-Frame-Options header in Rockwell Automation MicroLogix 1100/1400 Versions 21.007 and prior is not configured in the HTTP response, which could allow clickjacking attacks.

Affected products

Remediation

Vendor solution

Rockwell Automation encourages those using the affected software to implement the mitigations below to minimize risk. Additionally, Rockwell Automation encourages users to combine risk mitigations with security best practices (also provided below) to deploy a defense-in-depth strategy.

Disable the web server where possible (this component is an optional feature and disabling it will not disrupt the intended use of the device). Configure firewalls to disallow network communication through HTTP/Port 80

If applying the mitigations noted above are not possible, please see Rockwell Automation’s Knowledgebase article QA43240 Security Best Practices.

For more information, please see the industrial security advisory from Rockwell Automation.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Jul 20, 2022
Updated Apr 16, 2025
Reserved Jun 22, 2022
CISA Vulnrichment
Updated Apr 16, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner icscert
Published Jul 20, 2022
Updated Apr 16, 2025
Exploited since n/a
EUVD-2022-34463