CVE-2022-3157
Rockwell Automation GuardLogix and ControlLogix controllers Vulnerable to Denial-Of-Service Attack
Severity Score
7.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Attend
*SSVC
Descriptions
A vulnerability exists in the Rockwell Automation controllers that allows a malformed CIP request to cause a major non-recoverable fault (MNRF) and a denial-of-service condition (DOS).
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Attend
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-09-07 CVE Reserved
- 2022-12-16 CVE Published
- 2025-03-30 EPSS Updated
- 2025-04-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
- CAPEC-123: Buffer Manipulation
References (0)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Rockwellautomation Search vendor "Rockwellautomation" | Compactlogix 5370 Firmware Search vendor "Rockwellautomation" for product "Compactlogix 5370 Firmware" | >= 20 <= 33 Search vendor "Rockwellautomation" for product "Compactlogix 5370 Firmware" and version " >= 20 <= 33" | - |
Affected
| in | Rockwellautomation Search vendor "Rockwellautomation" | Compactlogix 5370 Search vendor "Rockwellautomation" for product "Compactlogix 5370" | - | - |
Safe
|
Rockwellautomation Search vendor "Rockwellautomation" | Compact Guardlogix 5370 Firmware Search vendor "Rockwellautomation" for product "Compact Guardlogix 5370 Firmware" | >= 28 <= 33 Search vendor "Rockwellautomation" for product "Compact Guardlogix 5370 Firmware" and version " >= 28 <= 33" | - |
Affected
| in | Rockwellautomation Search vendor "Rockwellautomation" | Compact Guardlogix 5370 Search vendor "Rockwellautomation" for product "Compact Guardlogix 5370" | - | - |
Safe
|
Rockwellautomation Search vendor "Rockwellautomation" | Compact Guardlogix 5380 Firmware Search vendor "Rockwellautomation" for product "Compact Guardlogix 5380 Firmware" | >= 28 <= 33 Search vendor "Rockwellautomation" for product "Compact Guardlogix 5380 Firmware" and version " >= 28 <= 33" | - |
Affected
| in | Rockwellautomation Search vendor "Rockwellautomation" | Compact Guardlogix 5380 Search vendor "Rockwellautomation" for product "Compact Guardlogix 5380" | - | - |
Safe
|
Rockwellautomation Search vendor "Rockwellautomation" | Controllogix 5570 Firmware Search vendor "Rockwellautomation" for product "Controllogix 5570 Firmware" | >= 20 <= 33 Search vendor "Rockwellautomation" for product "Controllogix 5570 Firmware" and version " >= 20 <= 33" | - |
Affected
| in | Rockwellautomation Search vendor "Rockwellautomation" | Controllogix 5570 Search vendor "Rockwellautomation" for product "Controllogix 5570" | - | - |
Safe
|
Rockwellautomation Search vendor "Rockwellautomation" | Controllogix 5570 Redundancy Firmware Search vendor "Rockwellautomation" for product "Controllogix 5570 Redundancy Firmware" | >= 20 <= 33 Search vendor "Rockwellautomation" for product "Controllogix 5570 Redundancy Firmware" and version " >= 20 <= 33" | - |
Affected
| in | Rockwellautomation Search vendor "Rockwellautomation" | Controllogix 5570 Redundancy Search vendor "Rockwellautomation" for product "Controllogix 5570 Redundancy" | - | - |
Safe
|
Rockwellautomation Search vendor "Rockwellautomation" | Guardlogix 5570 Firmware Search vendor "Rockwellautomation" for product "Guardlogix 5570 Firmware" | >= 20 <= 33 Search vendor "Rockwellautomation" for product "Guardlogix 5570 Firmware" and version " >= 20 <= 33" | - |
Affected
| in | Rockwellautomation Search vendor "Rockwellautomation" | Guardlogix 5570 Search vendor "Rockwellautomation" for product "Guardlogix 5570" | - | - |
Safe
|