Vulnerabilities > CVE-2022-1797 - Unspecified vulnerability in Rockwellautomation products

047910
CVSS 8.6 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
rockwellautomation

Summary

A malformed Class 3 common industrial protocol message with a cached connection can cause a denial-of-service condition in Rockwell Automation Logix Controllers, resulting in a major nonrecoverable fault. If the target device becomes unavailable, a user would have to clear the fault and redownload the user project file to bring the device back online.

Vulnerable Configurations

Part Description Count
OS
Rockwellautomation
29
Hardware
Rockwellautomation
9