ICSA-22-090-05 Rockwell Automation Logix Controllers
CVE-2022-1161

10CRITICAL

Summary

An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a separate location than the executed compiled code, allowing an attacker to change one and not the other.

Affected Version(s)

1768 CompactLogix controllers All all

1769 CompactLogix controllers all

Compact GuardLogix 5370 controllers all

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sharon Brizinov and Tal Keren of Claroty reported this vulnerability to CISA.
.