578
VMScore

CVE-2022-1159

Published: 01/04/2022 Updated: 08/04/2022
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Rockwell Automation Studio 5000 Logix Designer (all versions) are vulnerable when an attacker who achieves administrator access on a workstation running Studio 5000 Logix Designer could inject controller code undetectable to a user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rockwellautomation controllogix_5580_firmware

rockwellautomation guardlogix_5580_firmware

rockwellautomation compactlogix_5380_firmware

rockwellautomation compactlogix_5480_firmware

rockwellautomation compact_guardlogix_5380_firmware

Recent Articles

Rockwell Automation warns admins to take ICS devices offline
BleepingComputer • Sergiu Gatlan • 21 May 2024

Rockwell Automation warns admins to take ICS devices offline By Sergiu Gatlan May 21, 2024 01:48 PM 0 Rockwell Automation warned customers to disconnect all industrial control systems (ICSs) not designed for online exposure from the Internet due to increasing malicious activity worldwide. Network defenders should never configure such devices to allow remote connections from systems outside the local network. By taking them offline, they can drastically reduce their organizations' attack surface....