Rockwell Automation has an update available to handle an improper input validation vulnerability in its GuardLogix, ControlLogix, Compact Logix, and Compact GaurdLogix controllers, according to a report with CISA.

Successful exploitation of this remotely exploitable vulnerability, which Rockwell self-reported, could potentially lead to degradation in availability of the controller and/or a possible major nonrecoverable fault.

Rockwell said the vulnerability affects the following controllers:

  • CompactLogix 5370 Versions 20–33
  • Compact GuardLogix 5370 Versions 28–33
  • ControlLogix 5570 Versions 20–33
  • ControlLogix5570 redundancy Versions 20–33
  • GuardLogix 5570 Versions 20–33

In the vulnerability, an improper input validation issue exists in affected versions of Rockwell Automation controllers that could allow a malformed CIP request to cause a major nonrecoverable fault and a denial-of-service condition.

Schneider Bold

CVE-2022-3157 is the case number assigned to this vulnerability, which has as CVSS v3 base score of 8.6.

The product sees use in multiple industrial sectors, and on a global basis.

No known public exploits specifically target this vulnerability. However, an attacker with low skill level could leverage this low complexity vulnerability.

Rockwell released product updates addressing this vulnerability:

  • For CompactLogix 5370, Compact GuardLogix 5370, ControlLogix 5570, GuardLogix 5570: Users should upgrade to versions 33.013, 34.011, or later
  • For ControlLogix 5570 redundancy: Users should upgrade to versions 33.052, 34.051, or later

Users can apply mitigations on the Rockwell security best practices web page to reduce risk.

ISSSource

Pin It on Pinterest

Share This