CVE Database
/

CVE-2022-1797

Back to search

CVE-2022-1797

Published: May 31, 2022

Modified: Apr 16, 2025

PUBLISHED

CVSS v3.1

6.8

MEDIUM

Description

A malformed Class 3 common industrial protocol message with a cached connection can cause a denial-of-service condition in Rockwell Automation Logix Controllers, resulting in a major nonrecoverable fault. If the target device becomes unavailable, a user would have to clear the fault and redownload the user project file to bring the device back online.

VendorProductVersions

Rockwell Automation

CompactLogix 5380 controllers

affected
unspecified - <= 32.013

Rockwell Automation

Compact GuardLogix 5380 controllers

affected
unspecified - <= 32.013

Rockwell Automation

CompactLogix 5480 controllers

affected
unspecified - <= 32.013

Rockwell Automation

ControlLogix 5580 controllers

affected
unspecified - <= 32.013

Rockwell Automation

GuardLogix 5580 controllers

affected
unspecified - <= 32.013

Rockwell Automation

CompactLogix 5370 controllers

affected
unspecified - <= 33.013

Rockwell Automation

Compact GuardLogix 5370 controllers

affected
unspecified - <= 33.013

Rockwell Automation

ControlLogix 5570 controllers

affected
unspecified - <= 33.013

Rockwell Automation

GuardLogix 5570 controllers

affected
33.013

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H

Attack Vector

Network

Attack Complexity

High

Privileges Required

None

User Interaction

None

Scope

Changed

Confidentiality

None

Integrity

None

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now