7.5
CVSSv2

CVE-2022-1161

Published: 11/04/2022 Updated: 18/04/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a separate location than the executed compiled code, allowing an malicious user to change one and not the other.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rockwellautomation compactlogix_1768-l43_firmware

rockwellautomation compactlogix_1768-l45_firmware

rockwellautomation compactlogix_1769-l31_firmware

rockwellautomation compactlogix_1769-l32c_firmware

rockwellautomation compactlogix_1769-l32e_firmware

rockwellautomation compactlogix_1769-l35cr_firmware

rockwellautomation compactlogix_1769-l35e_firmware

rockwellautomation compactlogix_5370_l3_firmware

rockwellautomation compactlogix_5370_l2_firmware

rockwellautomation compactlogix_5370_l1_firmware

rockwellautomation compactlogix_5380_firmware

rockwellautomation compactlogix_5480_firmware

rockwellautomation compact_guardlogix_5370_firmware

rockwellautomation compact_guardlogix_5380_firmware

rockwellautomation controllogix_5550_firmware

rockwellautomation controllogix_5560_firmware

rockwellautomation controllogix_5570_firmware

rockwellautomation controllogix_5580_firmware

rockwellautomation guardlogix_5560_firmware

rockwellautomation guardlogix_5570_firmware

rockwellautomation guardlogix_5580_firmware

rockwellautomation flexlogix_1794-l34_firmware

rockwellautomation drivelogix_5730_firmware

rockwellautomation softlogix_5800_firmware