A vulnerability exists in the Rockwell Automation controllers that allows a malformed CIP request to cause a major non-recoverable fault (MNRF) and a denial-of-service condition (DOS).
References
| Link | Resource |
|---|---|
| https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1137757 | Permissions Required Vendor Advisory |
| https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1137757 | Permissions Required Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
History
21 Nov 2024, 07:18
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1137757 - Permissions Required, Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.6 |
22 Dec 2022, 19:18
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:rockwellautomation:guardlogix_5570_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:rockwellautomation:compact_guardlogix_5370_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:rockwellautomation:controllogix_5570_redundancy_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:rockwellautomation:controllogix_5570_redundancy:-:*:*:*:*:*:*:* cpe:2.3:h:rockwellautomation:guardlogix_5570:-:*:*:*:*:*:*:* cpe:2.3:o:rockwellautomation:controllogix_5570_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:rockwellautomation:compactlogix_5370:-:*:*:*:*:*:*:* cpe:2.3:o:rockwellautomation:compactlogix_5370_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:rockwellautomation:compact_guardlogix_5370:-:*:*:*:*:*:*:* cpe:2.3:o:rockwellautomation:compact_guardlogix_5380_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:rockwellautomation:controllogix_5570:-:*:*:*:*:*:*:* cpe:2.3:h:rockwellautomation:compact_guardlogix_5380:-:*:*:*:*:*:*:* |
|
| CWE | NVD-CWE-noinfo | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| References | (MISC) https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1137757 - Permissions Required, Vendor Advisory |
16 Dec 2022, 22:03
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2022-12-16 21:15
Updated : 2024-11-21 07:18
NVD link : CVE-2022-3157
Mitre link : CVE-2022-3157
CVE.ORG link : CVE-2022-3157
JSON object : View
Products Affected
rockwellautomation
- compact_guardlogix_5370_firmware
- compact_guardlogix_5380_firmware
- controllogix_5570_firmware
- guardlogix_5570
- controllogix_5570_redundancy
- compactlogix_5370
- compact_guardlogix_5370
- controllogix_5570
- guardlogix_5570_firmware
- controllogix_5570_redundancy_firmware
- compact_guardlogix_5380
- compactlogix_5370_firmware
CWE
