ICSA-22-090-05 Rockwell Automation Logix Controllers
CVE-2022-1161
10CRITICAL
Summary
An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a separate location than the executed compiled code, allowing an attacker to change one and not the other.
Affected Version(s)
1768 CompactLogix controllers All all
1769 CompactLogix controllers all
Compact GuardLogix 5370 controllers all
References
CVSS V3.1
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Sharon Brizinov and Tal Keren of Claroty reported this vulnerability to CISA.