Lucene search

K
cvelistRockwellCVELIST:CVE-2022-3752
HistoryDec 19, 2022 - 10:23 p.m.

CVE-2022-3752 Rockwell Automation GuardLogix and ControlLogix controllers Vulnerable to Denial-Of-Service Attack

2022-12-1922:23:36
CWE-20
Rockwell
www.cve.org
3
cve-2022-3752
rockwell automation
guardlogix
controllogix
denial-of-service
ethernet/ip
non-recoverable fault
unauthorized user
user project file
normal operation

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

AI Score

8.5

Confidence

High

EPSS

0.001

Percentile

26.4%

An unauthorized user could use a specially crafted sequence of Ethernet/IP messages, combined with heavy traffic
loading to cause a denial-of-service condition in Rockwell Automation Logix controllers resulting in a major non-recoverable fault. If the target device becomes unavailable, a user would have to clear the fault and redownload
the user project file to bring the device back online and continue normal operation.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "CompactLogix 5480",
    "vendor": "Rockwell Automation",
    "versions": [
      {
        "status": "affected",
        "version": "32.011 and later"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "ControlLogix 5580 ",
    "vendor": "Rockwell Automation",
    "versions": [
      {
        "status": "affected",
        "version": "31.011 and later"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "GuardLogix 5580",
    "vendor": "Rockwell Automation",
    "versions": [
      {
        "status": "affected",
        "version": "31.011 and later"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Compact GuardLogix 5380",
    "vendor": "Rockwell Automation",
    "versions": [
      {
        "status": "affected",
        "version": "31.011 and later"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "CompactLogix 5380",
    "vendor": "Rockwell Automation",
    "versions": [
      {
        "status": "affected",
        "version": "31.011 and later"
      }
    ]
  }
]

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

AI Score

8.5

Confidence

High

EPSS

0.001

Percentile

26.4%

Related for CVELIST:CVE-2022-3752