NA

CVE-2022-46670

Published: 16/12/2022 Updated: 07/11/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology that the MicroLogix 1100 and 1400 controllers contain a vulnerability that may give an attacker the ability to accomplish remote code execution.  The vulnerability is an unauthenticated stored cross-site scripting vulnerability in the embedded webserver. The payload is transferred to the controller over SNMP and is rendered on the homepage of the embedded website.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rockwellautomation micrologix_1400_firmware -

rockwellautomation micrologix_1100_firmware -

rockwellautomation micrologix_1400-b_firmware

rockwellautomation micrologix_1400-c_firmware

rockwellautomation micrologix_1400-a_firmware