PT-2022-2353 · Rockwell Automation · Rockwell Automation Studio 5000 Logix Designer+5

Sharon Brizinov

+1

·

Published

2022-04-01

·

Updated

2024-05-22

·

CVE-2022-1159

CVSS v3.1

7.7

High

VectorAV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rockwell Automation Studio 5000 Logix Designer (all versions) ControlLogix 5580 (affected versions not specified) GuardLogix 5580 (affected versions not specified) CompactLogix 5380 (affected versions not specified) CompactLogix 5480 (affected versions not specified) Compact GuardLogix 5380 (affected versions not specified)
Description The issue is related to incorrect code generation management in the programmable logic controllers' firmware. An attacker with administrator access on a workstation running Studio 5000 Logix Designer could inject controller code that is undetectable to a user. This could allow an attacker to embed controller code that a user cannot detect.
Recommendations For Rockwell Automation Studio 5000 Logix Designer, restrict access to administrator privileges on workstations to minimize the risk of exploitation. For ControlLogix 5580, consider disabling code injection functionality until a fix is available. For GuardLogix 5580, restrict access to the controller code generation management module to minimize the risk of exploitation. For CompactLogix 5380, avoid using the code generation feature in the affected firmware until the issue is resolved. For CompactLogix 5480, consider implementing additional security measures to detect and prevent code injection. For Compact GuardLogix 5380, restrict access to the vulnerable code generation management functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2022-02661
CVE-2022-1159

Affected Products

Compact Guardlogix 5380
Compactlogix 5380
Compactlogix 5480
Controllogix 5580
Guardlogix 5580
Rockwell Automation Studio 5000 Logix Designer