Input validation error in Rockwell Automation products - CVE-2022-3752
Published: December 9, 2022
Vulnerability identifier: #VU70085
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-3752
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can use a specially crafted sequence of Ethernet and IP messages and perform a denial of service (DoS) attack.
Affected software
CompactLogix 5380
Compact GuardLogix 5380
CompactLogix 5480
ControlLogix 5580
GuardLogix 5580
Compact GuardLogix 5380
CompactLogix 5480
ControlLogix 5580
GuardLogix 5580
How to mitigate CVE-2022-3752
Install updates from vendor's website.
CompactLogix 5380 - addressed in versions 32.016, 33.015, 34.011
Compact GuardLogix 5380 - addressed in versions 32.016, 33.015, 34.011
CompactLogix 5480 - addressed in versions 32.016, 33.015, 34.011
ControlLogix 5580 - addressed in versions 32.016, 33.015, 34.011
GuardLogix 5580 - addressed in versions 32.016, 33.015, 34.011
Compact GuardLogix 5380 - addressed in versions 32.016, 33.015, 34.011
CompactLogix 5480 - addressed in versions 32.016, 33.015, 34.011
ControlLogix 5580 - addressed in versions 32.016, 33.015, 34.011
GuardLogix 5580 - addressed in versions 32.016, 33.015, 34.011