Vulnerabilities > CVE-2022-1161 - Inclusion of Functionality from Untrusted Control Sphere vulnerability in Rockwellautomation products

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
rockwellautomation
CWE-829

Summary

An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a separate location than the executed compiled code, allowing an attacker to change one and not the other.

Vulnerable Configurations

Part Description Count
OS
Rockwellautomation
24
Hardware
Rockwellautomation
24