CVE-2022-3157: Rockwell Automation GuardLogix and ControlLogix controllers Vulnerable to Denial-Of-Service Attack
A vulnerability exists in the Rockwell Automation controllers that allows a malformed CIP request to cause a major non-recoverable fault (MNRF) and a denial-of-service condition (DOS).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-3157?
CVE-2022-3157 is a vulnerability that exists in the Rockwell Automation controllers and can cause a major non-recoverable fault (MNRF) and a denial-of-service (DoS) condition.
What is the severity of CVE-2022-3157?
CVE-2022-3157 has a severity value of 7.5, which is considered high.
Which software versions are affected by CVE-2022-3157?
CVE-2022-3157 affects Rockwell Automation CompactLogix 5370 Firmware versions 20 to 33, and Compact GuardLogix 5370/5380 Firmware versions 28 to 33.
How can CVE-2022-3157 be exploited?
CVE-2022-3157 can be exploited by sending a malformed CIP request to the vulnerable Rockwell Automation controllers.
How can I fix CVE-2022-3157?
To fix CVE-2022-3157, it is recommended to apply the necessary security patches and updates provided by Rockwell Automation.