Inclusion of Functionality from Untrusted Control Sphere in Rockwell Automation products - CVE-2022-1161

 

Inclusion of Functionality from Untrusted Control Sphere in Rockwell Automation products - CVE-2022-1161

Published: April 1, 2022


Vulnerability identifier: #VU61791
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-1161
CWE-ID: CWE-829
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to inclusion of functionality from untrusted control sphere. A remote attacker with the ability to modify a user program can change user program code on some control systems and execute arbitrary code on the target system.


Affected software

ControlLogix 5560
SoftLogix 5800
DriveLogix 5730
FlexLogix 1794-L34
GuardLogix 5580
GuardLogix 5570
GuardLogix 5560
ControlLogix 5580
ControlLogix 5570
1768 CompactLogix
ControlLogix 5550
Compact GuardLogix 5380
Compact GuardLogix 5370
CompactLogix 5480
CompactLogix 5380
CompactLogix 5370
1769 CompactLogix

How to mitigate CVE-2022-1161

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins