ZeroHour

CVE-2022-1161

CVSS 3.1
9.8 critical
EPSS
5%p92
Published
()
Modified
Description

An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a separate location than the executed compiled code, allowing an attacker to change one and not the other.

Vendors
rockwellautomation
Products
compactlogix 1768-l43 firmware, compactlogix 1768-l45 firmware, compactlogix 1769-l31 firmware, compactlogix 1769-l32c firmware, compactlogix 1769-l32e firmware, compactlogix 1769-l35cr firmware, compactlogix 1769-l35e firmware, compactlogix 5370 l3 firmware, compactlogix 5370 l2 firmware, compactlogix 5370 l1 firmware, compactlogix 5380 firmware, compactlogix 5480 firmware
Weakness
CWE-829
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news