Rockwell Automation MicroLogix 1100 & 1400 Vulnerable to Cross-Site Scripting Attack
CVE-2022-46670
Key Information:
- Vendor
Rockwell Automation
- Vendor
- CVE Published:
- 16 December 2022
What is CVE-2022-46670?
Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology that the MicroLogix 1100 and 1400 controllers contain a vulnerability that may give an attacker the ability to accomplish remote code execution.  The vulnerability is an unauthenticated stored cross-site scripting vulnerability in the embedded webserver. The payload is transferred to the controller over SNMP and is rendered on the homepage of the embedded website.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MicroLogix 1100 & 1400 Controllers All
MicroLogix 1400-A 7.000 and below
MicroLogix 1400-B/C 21.007 and below
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved