Resource exhaustion in Rockwell Automation products - CVE-2022-1797

 

Resource exhaustion in Rockwell Automation products - CVE-2022-1797

Published: May 25, 2022


Vulnerability identifier: #VU63626
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-1797
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can use a specially crafted Class 3 common industrial protocol message, trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

CompactLogix 5380
Compact GuardLogix 5380
GuardLogix 5570
CompactLogix 5480
ControlLogix 5570
ControlLogix 5580
Compact GuardLogix 5370
GuardLogix 5580
CompactLogix 5370

How to mitigate CVE-2022-1797

Install updates from vendor's website.

CompactLogix 5380 - update to 33.011
Compact GuardLogix 5380 - update to 33.011
GuardLogix 5570 - update to 34.011
CompactLogix 5480 - update to 33.011
ControlLogix 5570 - update to 34.011
ControlLogix 5580 - update to 33.011
Compact GuardLogix 5370 - update to 34.011
GuardLogix 5580 - update to 33.011
CompactLogix 5370 - update to 34.011

External References

Related Security Bulletins