HIGH
Rockwell Automation GuardLogix and ControlLogix controllers Vulnerable to Denial-Of-Service Attack
Published Dec 16, 2022
8.6
HIGHCVSS 3.1
EPSS 1.47%
Description
A vulnerability exists in the Rockwell Automation controllers that allows a malformed CIP request to cause a major non-recoverable fault (MNRF) and a denial-of-service condition (DOS).
Affected products
-
- Version 28StatusaffectedConstraints<=33
- Version
-
- Version 20StatusaffectedConstraints<=33
- Version
-
- Version 20StatusaffectedConstraints<=33
- Version
-
- Version 20StatusaffectedConstraints<=33
- Version
-
- Version 20StatusaffectedConstraints<=33
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Rockwell Automation | Compact GuardLogix | unaffected |
| ||||||
| Rockwell Automation | CompactLogix 5370 | unaffected |
| ||||||
| Rockwell Automation | ControlLogix 5570 | unaffected |
| ||||||
| Rockwell Automation | ControlLogix 5570 Redundancy | unaffected |
| ||||||
| Rockwell Automation | GuardLogix 5570 | unaffected |
|
Configuration 1
AND
- ≥ 20 · ≤ 33
Running on/with
- n/a
Configuration 2
AND
- ≥ 28 · ≤ 33
Running on/with
- n/a
Configuration 3
AND
- ≥ 28 · ≤ 33
Running on/with
- n/a
Configuration 4
AND
- ≥ 20 · ≤ 33
Running on/with
- n/a
Configuration 5
AND
- ≥ 20 · ≤ 33
Running on/with
- n/a
Configuration 6
AND
- ≥ 20 · ≤ 33
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (1)
- https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1137757 Permissions RequiredVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1137757 | Permissions RequiredVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Rockwell
Published Dec 16, 2022
Updated Apr 16, 2025
Reserved Sep 7, 2022
Link CVE-2022-3157
CISA Vulnrichment
Updated Apr 16, 2025