Input validation error in Rockwell Automation products - CVE-2022-3157
Published: January 3, 2023
Vulnerability identifier: #VU70642
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-3157
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted CIP request and perform a denial of service (DoS) attack.
Affected software
CompactLogix 5370
Compact GuardLogix 5370
ControlLogix 5570
ControlLogix 5570 redundancy
GuardLogix 5570
Compact GuardLogix 5370
ControlLogix 5570
ControlLogix 5570 redundancy
GuardLogix 5570
How to mitigate CVE-2022-3157
Install updates from vendor's website.
CompactLogix 5370 - addressed in versions 33.013, 34.011
Compact GuardLogix 5370 - addressed in versions 33.013, 34.011
ControlLogix 5570 - addressed in versions 33.013, 34.011
ControlLogix 5570 redundancy - addressed in versions 33.052, 34.051
GuardLogix 5570 - addressed in versions 33.013, 34.011
Compact GuardLogix 5370 - addressed in versions 33.013, 34.011
ControlLogix 5570 - addressed in versions 33.013, 34.011
ControlLogix 5570 redundancy - addressed in versions 33.052, 34.051
GuardLogix 5570 - addressed in versions 33.013, 34.011