← Back

CVE-2022-1161

nvd nist
Published: Apr 11, 2022Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a separate location than the executed compiled code, allowing an attacker to change one and not the other.

Affected (24)

Compactlogix 1768 L43 Firmware
Compactlogix 1768 L45 Firmware
Compactlogix 1769 L31 Firmware
Compactlogix 1769 L32c Firmware
Compactlogix 1769 L32e Firmware
Compactlogix 1769 L35cr Firmware
Compactlogix 1769 L35e Firmware
Compactlogix 5370 L3 Firmware
Compactlogix 5370 L2 Firmware
Compactlogix 5370 L1 Firmware
Compactlogix 5380 Firmware
Compactlogix 5480 Firmware
Compact Guardlogix 5370 Firmware
Compact Guardlogix 5380 Firmware
Controllogix 5550 Firmware
Controllogix 5560 Firmware
Controllogix 5570 Firmware
Controllogix 5580 Firmware
Guardlogix 5560 Firmware
Guardlogix 5570 Firmware
Guardlogix 5580 Firmware
Flexlogix 1794 L34 Firmware
Drivelogix 5730 Firmware
Softlogix 5800 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Compactlogix 1768 L43
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Compactlogix 1768 L45
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Compactlogix 1769 L31
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Compactlogix 1769 L32c
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Compactlogix 1769 L32e
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Compactlogix 1769 L35cr
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Compactlogix 1769 L35e
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Compactlogix 5370 L3
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Compactlogix 5370 L2
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Compactlogix 5370 L1
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Compactlogix 5380
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Compactlogix 5480
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Compact Guardlogix 5370
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Compact Guardlogix 5380
All versions
Configuration O
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Controllogix 5550
All versions
Configuration P
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Controllogix 5560
All versions
Configuration Q
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Controllogix 5570
All versions
Configuration R
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Controllogix 5580
All versions
Configuration S
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Guardlogix 5560
All versions
Configuration T
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Guardlogix 5570
All versions
Configuration U
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Guardlogix 5580
All versions
Configuration V
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Flexlogix 1794 L34
All versions
Configuration W
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Drivelogix 5730
All versions
Configuration X
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Softlogix 5800
All versions

References (2)

Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.