CVE-2022-1161

CRITICALCVSS 9.8/10EPSS 4.87%

Last modified

CVE-2022-1161 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a separate location than the executed compiled code, allowing an attacker to change one and not the other.. EPSS estimates a 4.87% chance of exploitation in the next 30 days.

Description

An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a separate location than the executed compiled code, allowing an attacker to change one and not the other.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
4.87%

90.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
RockwellautomationCompactlogix 1768-L43 FirmwareAll versions
RockwellautomationCompactlogix 1768-L45 FirmwareAll versions
RockwellautomationCompactlogix 1769-L31 FirmwareAll versions
RockwellautomationCompactlogix 1769-L32c FirmwareAll versions
RockwellautomationCompactlogix 1769-L32e FirmwareAll versions
RockwellautomationCompactlogix 1769-L35cr FirmwareAll versions
RockwellautomationCompactlogix 1769-L35e FirmwareAll versions
RockwellautomationCompactlogix 5370 L3 FirmwareAll versions
RockwellautomationCompactlogix 5370 L2 FirmwareAll versions
RockwellautomationCompactlogix 5370 L1 FirmwareAll versions
RockwellautomationCompactlogix 5380 FirmwareAll versions
RockwellautomationCompactlogix 5480 FirmwareAll versions
RockwellautomationCompact Guardlogix 5370 FirmwareAll versions
RockwellautomationCompact Guardlogix 5380 FirmwareAll versions
RockwellautomationControllogix 5550 FirmwareAll versions
RockwellautomationControllogix 5560 FirmwareAll versions
RockwellautomationControllogix 5570 FirmwareAll versions
RockwellautomationControllogix 5580 FirmwareAll versions
RockwellautomationGuardlogix 5560 FirmwareAll versions
RockwellautomationGuardlogix 5570 FirmwareAll versions
RockwellautomationGuardlogix 5580 FirmwareAll versions
RockwellautomationFlexlogix 1794-L34 FirmwareAll versions
RockwellautomationDrivelogix 5730 FirmwareAll versions
RockwellautomationSoftlogix 5800 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-1161?
An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a separate location than the executed compiled code, allowing an attacker to change one and not the other.
How severe is CVE-2022-1161?
CVE-2022-1161 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 4.87% probability of exploitation in the next 30 days.
How do I fix CVE-2022-1161?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-1161?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST