ZeroHour

CVE-2022-46670

CVSS 3.1
6.1 medium
EPSS
<1%p44
Published
()
Modified
Description

Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology that the MicroLogix 1100 and 1400 controllers contain a vulnerability that may give an attacker the ability to accomplish remote code execution. The vulnerability is an unauthenticated stored cross-site scripting vulnerability in the embedded webserver. The payload is transferred to the controller over SNMP and is rendered on the homepage of the embedded website.

Vendors
rockwellautomation
Products
micrologix 1400 firmware, micrologix 1100 firmware, micrologix 1400-b firmware, micrologix 1400-c firmware, micrologix 1400-a firmware
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.