PT-2022-27942 · Allen Bradley · Micrologix 1400+1

Published

2022-12-13

·

Updated

2022-12-22

·

CVE-2022-46670

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MicroLogix 1100 and 1400 controllers (affected versions not specified)
Description The issue is an unauthenticated stored cross-site scripting vulnerability in the embedded webserver of the controllers. This may allow an attacker to accomplish remote code execution. The payload is transferred to the controller over SNMP and is rendered on the homepage of the embedded website.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-05556
CVE-2022-46670

Affected Products

Micrologix 1100
Micrologix 1400