CVE-2022-1159: Rockwell Automation Studio 5000 Logix Designer Code Injection
Rockwell Automation Studio 5000 Logix Designer (all versions) are vulnerable when an attacker who achieves administrator access on a workstation running Studio 5000 Logix Designer could inject controller code undetectable to a user.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-1159?
CVE-2022-1159 is a vulnerability in Rockwell Automation Studio 5000 Logix Designer that allows an attacker who achieves administrator access to inject controller code undetectable to a user.
What is the severity of CVE-2022-1159?
CVE-2022-1159 has a severity rating of 7.2 (high).
Which versions of Rockwell Automation Studio 5000 Logix Designer are affected?
All versions of Rockwell Automation Studio 5000 Logix Designer are vulnerable to CVE-2022-1159.
How can an attacker exploit CVE-2022-1159?
An attacker with administrator access on a workstation running Studio 5000 Logix Designer can inject controller code that is undetectable to a user.
Is there a fix for CVE-2022-1159?
At the moment, there is no fix available for CVE-2022-1159. It is recommended to follow the mitigation steps provided by Rockwell Automation and monitor for any updates from the vendor.