ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Critical Bugs in Rockwell PLC Could Allow Hackers to Implant Malicious Code

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-1159
Rockwell Automation Studio 5000 Logix Designer (all versions) are vulnerable when an attacker who achieves administrator access on a workstation running Studio

Rockwell Automation Studio 5000 Logix Designer (all versions) are vulnerable when an attacker who achieves administrator access on a workstation running Studio 5000 Logix Designer could inject controller code undetectable to a user.

NVD description · AI analysis pending
7.23%
  • rockwellautomation controllogix 5580 firmware
  • rockwellautomation guardlogix 5580 firmware
  • rockwellautomation compactlogix 5380 firmware
  • +1 more
CVE-2022-1161
An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems.

An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a separate location than the executed compiled code, allowing an attacker to change one and not the other.

NVD description · AI analysis pending
9.85%
  • rockwellautomation compactlogix 1768-l43 firmware
  • rockwellautomation compactlogix 1768-l45 firmware
  • rockwellautomation compactlogix 1769-l31 firmware
  • +1 more
Full article339 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananApr 01, 2022

Two new security vulnerabilities have been disclosed in Rockwell Automation's programmable logic controllers (PLCs) and engineering workstation software that could be exploited by an attacker to inject malicious code on affected systems and stealthily modify automation processes.

The flaws have the potential to disrupt industrial operations and cause physical damage to factories in a manner similar to that of Stuxnet and the Rogue7 attacks, operational technology security company Claroty said.

"Programmable logic and predefined variables drive these [automation] processes, and changes to either will alter normal operation of the PLC and the process it manages," Claroty's Sharon Brizinov noted in a write-up published Thursday.

The list of two flaws is below –

  • CVE-2022-1161 (CVSS score: 10.0) – A remotely exploitable flaw that allows a malicious actor to write user-readable "textual" program code to a separate memory location from the executed compiled code (aka bytecode). The issue resides in PLC firmware running on Rockwell's ControlLogix, CompactLogix, and GuardLogix control systems.
  • CVE-2022-1159 (CVSS score: 7.7) – An attacker with administrative access to a workstation running Studio 5000 Logix Designer application can intercept the compilation process and inject code into the user program without the user's knowledge.

Successful exploitation of the defects could allow an attacker to modify user programs and download malicious code to the controller, effectively altering the PLC's normal operation and allowing rogue commands to be sent to the physical devices controlled by the industrial system.

"The end result of exploiting both vulnerabilities is the same: The engineer believes that benign code is running on the PLC; meanwhile, completely different and potentially malicious code is being executed on the PLC," Brizinov explained.

The severity of the flaws has also prompted an advisory from the U.S. Cybersecurity and Infrastructure Security Agency (CISA) that outlines mitigation steps users of the affected hardware and software can take for a "comprehensive defense-in-depth strategy."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/04/critical-bugs-in-rockwell-plc-could.html