← Back

CVE-2022-46670

nvd nist
Published: Dec 16, 2022Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology that the MicroLogix 1100 and 1400 controllers contain a vulnerability that may give an attacker the ability to accomplish remote code execution.  The vulnerability is an unauthenticated stored cross-site scripting vulnerability in the embedded webserver. The payload is transferred to the controller over SNMP and is rendered on the homepage of the embedded website.

Affected (5)

Micrologix 1400 Firmware
Micrologix 1100 Firmware
Micrologix 1400 B Firmware
Micrologix 1400 C Firmware
Micrologix 1400 A Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Micrologix 1400
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Micrologix 1100
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 21.007
Running on/withPlatform Versions
Rockwellautomation
Micrologix 1400 B
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 21.007
Running on/withPlatform Versions
Rockwellautomation
Micrologix 1400 C
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 7.000
Running on/withPlatform Versions
Rockwellautomation
Micrologix 1400 A
All versions

References (2)

Source: PSIRT@rockwellautomation.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.