Rockwell Automation has an update available to handle an improper input validation vulnerability in its GuardLogix, ControlLogix, Compact Logix, and Compact GaurdLogix controllers, according to a report with CISA.
Successful exploitation of this remotely exploitable vulnerability, which Rockwell self-reported, could potentially lead to degradation in availability of the controller and/or a possible major nonrecoverable fault.
Rockwell said the vulnerability affects the following controllers:
- CompactLogix 5370 Versions 20–33
- Compact GuardLogix 5370 Versions 28–33
- ControlLogix 5570 Versions 20–33
- ControlLogix5570 redundancy Versions 20–33
- GuardLogix 5570 Versions 20–33
In the vulnerability, an improper input validation issue exists in affected versions of Rockwell Automation controllers that could allow a malformed CIP request to cause a major nonrecoverable fault and a denial-of-service condition.
CVE-2022-3157 is the case number assigned to this vulnerability, which has as CVSS v3 base score of 8.6.
The product sees use in multiple industrial sectors, and on a global basis.
No known public exploits specifically target this vulnerability. However, an attacker with low skill level could leverage this low complexity vulnerability.
Rockwell released product updates addressing this vulnerability:
- For CompactLogix 5370, Compact GuardLogix 5370, ControlLogix 5570, GuardLogix 5570: Users should upgrade to versions 33.013, 34.011, or later
- For ControlLogix 5570 redundancy: Users should upgrade to versions 33.052, 34.051, or later
Users can apply mitigations on the Rockwell security best practices web page to reduce risk.

