Vulnerability Description
An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a separate location than the executed compiled code, allowing an attacker to change one and not the other.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rockwellautomation | Compactlogix 1768-L43 Firmware | All versions |
| Rockwellautomation | Compactlogix 1768-L43 | - |
| Rockwellautomation | Compactlogix 1768-L45 Firmware | All versions |
| Rockwellautomation | Compactlogix 1768-L45 | - |
| Rockwellautomation | Compactlogix 1769-L31 Firmware | All versions |
| Rockwellautomation | Compactlogix 1769-L31 | - |
| Rockwellautomation | Compactlogix 1769-L32C Firmware | All versions |
| Rockwellautomation | Compactlogix 1769-L32C | - |
| Rockwellautomation | Compactlogix 1769-L32E Firmware | All versions |
| Rockwellautomation | Compactlogix 1769-L32E | - |
| Rockwellautomation | Compactlogix 1769-L35Cr Firmware | All versions |
| Rockwellautomation | Compactlogix 1769-L35Cr | - |
| Rockwellautomation | Compactlogix 1769-L35E Firmware | All versions |
| Rockwellautomation | Compactlogix 1769-L35E | - |
| Rockwellautomation | Compactlogix 5370 L3 Firmware | All versions |
| Rockwellautomation | Compactlogix 5370 L3 | - |
| Rockwellautomation | Compactlogix 5370 L2 Firmware | All versions |
| Rockwellautomation | Compactlogix 5370 L2 | - |
| Rockwellautomation | Compactlogix 5370 L1 Firmware | All versions |
| Rockwellautomation | Compactlogix 5370 L1 | - |
Related Weaknesses (CWE)
References
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-090-05Third Party AdvisoryUS Government Resource
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-090-05Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2022-1161?
CVE-2022-1161 is a vulnerability with a CVSS score of 10.0 (CRITICAL). An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable p...
How severe is CVE-2022-1161?
CVE-2022-1161 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-1161?
Check the references section above for vendor advisories and patch information. Affected products include: Rockwellautomation Compactlogix 1768-L43 Firmware, Rockwellautomation Compactlogix 1768-L43, Rockwellautomation Compactlogix 1768-L45 Firmware, Rockwellautomation Compactlogix 1768-L45, Rockwellautomation Compactlogix 1769-L31 Firmware.