CVE-2022-3157

A vulnerability exists in the Rockwell Automation controllers that allows a malformed CIP request to cause a major non-recoverable fault (MNRF) and a denial-of-service condition (DOS).
References
Link Resource
https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1137757 Permissions Required Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:h:rockwellautomation:compactlogix_5370:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:compactlogix_5370_firmware:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:h:rockwellautomation:compact_guardlogix_5370:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:compact_guardlogix_5370_firmware:*:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:h:rockwellautomation:compact_guardlogix_5380:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:compact_guardlogix_5380_firmware:*:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:h:rockwellautomation:controllogix_5570:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:controllogix_5570_firmware:*:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:h:rockwellautomation:controllogix_5570_redundancy:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:controllogix_5570_redundancy_firmware:*:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:h:rockwellautomation:guardlogix_5570:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:guardlogix_5570_firmware:*:*:*:*:*:*:*:*

History

07 Nov 2023, 03:50

Type Values Removed Values Added
Summary A vulnerability exists in the Rockwell Automation controllers that allows a malformed CIP request to cause a major non-recoverable fault (MNRF) and a denial-of-service condition (DOS). A vulnerability exists in the Rockwell Automation controllers that allows a malformed CIP request to cause a major non-recoverable fault (MNRF) and a denial-of-service condition (DOS).

22 Dec 2022, 19:18

Type Values Removed Values Added
References (MISC) https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1137757 - (MISC) https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1137757 - Permissions Required, Vendor Advisory
CPE cpe:2.3:o:rockwellautomation:compact_guardlogix_5370_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:compact_guardlogix_5380_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:controllogix_5570_redundancy_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:controllogix_5570:-:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:guardlogix_5570:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:controllogix_5570_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:compact_guardlogix_5370:-:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:controllogix_5570_redundancy:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:compactlogix_5370_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:compactlogix_5370:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:guardlogix_5570_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:compact_guardlogix_5380:-:*:*:*:*:*:*:*
First Time Rockwellautomation controllogix 5570 Redundancy Firmware
Rockwellautomation controllogix 5570 Redundancy
Rockwellautomation compact Guardlogix 5370 Firmware
Rockwellautomation guardlogix 5570 Firmware
Rockwellautomation compactlogix 5370
Rockwellautomation compactlogix 5370 Firmware
Rockwellautomation
Rockwellautomation compact Guardlogix 5370
Rockwellautomation controllogix 5570
Rockwellautomation guardlogix 5570
Rockwellautomation compact Guardlogix 5380 Firmware
Rockwellautomation controllogix 5570 Firmware
Rockwellautomation compact Guardlogix 5380
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

16 Dec 2022, 22:03

Type Values Removed Values Added
New CVE

Information

Published : 2022-12-16 21:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-3157

Mitre link : CVE-2022-3157

CVE.ORG link : CVE-2022-3157


JSON object : View

Products Affected

rockwellautomation

  • guardlogix_5570
  • controllogix_5570_redundancy
  • compact_guardlogix_5370_firmware
  • compactlogix_5370
  • controllogix_5570
  • compactlogix_5370_firmware
  • controllogix_5570_firmware
  • controllogix_5570_redundancy_firmware
  • compact_guardlogix_5380
  • guardlogix_5570_firmware
  • compact_guardlogix_5370
  • compact_guardlogix_5380_firmware
CWE
NVD-CWE-noinfo CWE-20

Improper Input Validation