QID 591250

Date Published: 2022-12-23

QID 591250: Rockwell Automation Logix controllers Improper Input Validation Vulnerability (ICSA-22-342-03)

AFFECTED PRODUCTS
CompactLogix 5380 controllers: firmware version 31.011 and later.
Compact GuardLogix 5380 controllers: firmware version 31.011 and later.
CompactLogix 5480 controllers: firmware version 32.011 and later.
ControlLogix 5580 controllers: firmware version 31.011 and later.
GuardLogix 5580 controllers: firmware version 31.011 and later.

QID Detection Logic:
This QID checks for the Vulnerable version of Rockwell Automation Logix controllers using passive scanning

Successful exploitation of this vulnerability could allow an unauthorized user to cause denial-of-service condition on a targeted device.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section icsa-22-342-03 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591250

    Software Advisories
    Advisory ID Software Component Link
    icsa-22-342-03 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-22-342-03