CVE Database
/

CVE-2022-1161

Back to search

CVE-2022-1161

Published: Apr 11, 2022

Modified: Apr 16, 2025

PUBLISHED

CVSS v3.1

10.0

CRITICAL

Description

An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a separate location than the executed compiled code, allowing an attacker to change one and not the other.

VendorProductVersions

Rockwell Automation

1768 CompactLogix controllers

affected
All all

Rockwell Automation

1769 CompactLogix controllers

affected
all

Rockwell Automation

CompactLogix 5370 controllers

affected
all

Rockwell Automation

CompactLogix 5380 controllers

affected
all

Rockwell Automation

CompactLogix 5480 controllers

affected
all

Rockwell Automation

Compact GuardLogix 5370 controllers

affected
all

Rockwell Automation

Compact GuardLogix 5380 controllers

affected
all

Rockwell Automation

ControlLogix 5550 controllers

affected
all

Rockwell Automation

ControlLogix 5560 controllers

affected
all

Rockwell Automation

ControlLogix 5570 controllers

affected
all

Rockwell Automation

ControlLogix 5580 controllers

affected
all

Rockwell Automation

GuardLogix 5560 controllers

affected
all

Rockwell Automation

GuardLogix 5570 controllers

affected
all

Rockwell Automation

GuardLogix 5580 controllers

affected
all

Rockwell Automation

FlexLogix 1794-L34 controllers

affected
all

Rockwell Automation

DriveLogix 5730 controllers

affected
all

Rockwell Automation

SoftLogix 5800 controllers

affected
all

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now