SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-1161

An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems.

CRITICAL 9.8EPSS 5.21%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (5.21%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a separate location than the executed compiled code, allowing an attacker to change one and not the other.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
5.21% probability · 92th percentile
CISA KEV
Not listed
Weakness
CWE-829
Affected
rockwellautomation/compactlogix 1768-l43 firmware · rockwellautomation/compactlogix 1768-l45 firmware · rockwellautomation/compactlogix 1769-l31 firmware · rockwellautomation/compactlogix 1769-l32c firmware · rockwellautomation/compactlogix 1769-l32e firmware · rockwellautomation/compactlogix 1769-l35cr firmware · rockwellautomation/compactlogix 1769-l35e firmware · rockwellautomation/compactlogix 5370 l3 firmware · rockwellautomation/compactlogix 5370 l2 firmware · rockwellautomation/compactlogix 5370 l1 firmware · rockwellautomation/compactlogix 5380 firmware · rockwellautomation/compactlogix 5480 firmware · rockwellautomation/compact guardlogix 5370 firmware · rockwellautomation/compact guardlogix 5380 firmware · rockwellautomation/controllogix 5550 firmware · rockwellautomation/controllogix 5560 firmware · rockwellautomation/controllogix 5570 firmware · rockwellautomation/controllogix 5580 firmware · rockwellautomation/guardlogix 5560 firmware · rockwellautomation/guardlogix 5570 firmware · +4 more
Source
ics-cert@hq.dhs.gov

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.