PT-2022-24017 · Rockwell Automation · Logix Controllers

Published

2022-12-19

·

Updated

2022-12-27

·

CVE-2022-3752

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Rockwell Automation Logix controllers (affected versions not specified)
Description An unauthorized user could use a specially crafted sequence of Ethernet/IP messages, combined with heavy traffic loading to cause a denial-of-service condition in the controllers, resulting in a major non-recoverable fault. If the target device becomes unavailable, a user would have to clear the fault and redownload the user project file to bring the device back online and continue normal operation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-3752

Affected Products

Logix Controllers