Vulnerability Description
A vulnerability exists in the Rockwell Automation controllers that allows a malformed CIP request to cause a major non-recoverable fault (MNRF) and a denial-of-service condition (DOS).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rockwellautomation | Compactlogix 5370 Firmware | >= 20, <= 33 |
| Rockwellautomation | Compactlogix 5370 | - |
| Rockwellautomation | Compact Guardlogix 5370 Firmware | >= 28, <= 33 |
| Rockwellautomation | Compact Guardlogix 5370 | - |
| Rockwellautomation | Compact Guardlogix 5380 Firmware | >= 28, <= 33 |
| Rockwellautomation | Compact Guardlogix 5380 | - |
| Rockwellautomation | Controllogix 5570 Firmware | >= 20, <= 33 |
| Rockwellautomation | Controllogix 5570 | - |
| Rockwellautomation | Controllogix 5570 Redundancy Firmware | >= 20, <= 33 |
| Rockwellautomation | Controllogix 5570 Redundancy | - |
| Rockwellautomation | Guardlogix 5570 Firmware | >= 20, <= 33 |
| Rockwellautomation | Guardlogix 5570 | - |
Related Weaknesses (CWE)
References
- https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1137757Permissions RequiredVendor Advisory
- https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1137757Permissions RequiredVendor Advisory
FAQ
What is CVE-2022-3157?
CVE-2022-3157 is a vulnerability with a CVSS score of 8.6 (HIGH). A vulnerability exists in the Rockwell Automation controllers that allows a malformed CIP request to cause a major non-recoverable fault (MNRF) and a denial-of-service condition (DOS).
How severe is CVE-2022-3157?
CVE-2022-3157 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-3157?
Check the references section above for vendor advisories and patch information. Affected products include: Rockwellautomation Compactlogix 5370 Firmware, Rockwellautomation Compactlogix 5370, Rockwellautomation Compact Guardlogix 5370 Firmware, Rockwellautomation Compact Guardlogix 5370, Rockwellautomation Compact Guardlogix 5380 Firmware.