QID 591372

Date Published: 2023-04-03

QID 591372: Rockwell Automation GuardLogix and ControlLogix controllers Improper Input Validation Vulnerability (icsa-22-354-02)

AFFECTED PRODUCTS
CompactLogix 5370 Versions 20-33
Compact GuardLogix 5370 Versions 28-33
ControlLogix 5570 Versions 20-33
ControlLogix5570 redundancy Versions 20-33
GuardLogix 5570 Versions 20-33

QID Detection Logic:
This QID checks for the Vulnerable version of Rockwell Automation GuardLogix and ControlLogix controllers using passive scanning.

Successful exploitation of this vulnerability could potentially lead to degradation in availability of the controller and/or a possible major nonrecoverable fault.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section icsa-22-354-02 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591372

    Software Advisories
    Advisory ID Software Component Link
    icsa-22-354-02 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-22-354-02