CVE-2022-3157

HIGH

Rockwell Automation CompactLogix 5370 Firmware 20-32 - Denial of Service via Malformed CIP Request

Title source: llm
STIX 2.1

Description

A vulnerability exists in the Rockwell Automation controllers that allows a malformed CIP request to cause a major non-recoverable fault (MNRF) and a denial-of-service condition (DOS).

References (1)

Core 1
Core References

Scores

CVSS v3 8.6
EPSS 0.0150
EPSS Percentile 81.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (6)
rockwellautomation/compact_guardlogix_5370_firmware 28 - 33
rockwellautomation/compact_guardlogix_5380_firmware 28 - 33
rockwellautomation/compactlogix_5370_firmware 20 - 33
rockwellautomation/controllogix_5570_firmware 20 - 33
rockwellautomation/controllogix_5570_redundancy_firmware 20 - 33
rockwellautomation/guardlogix_5570_firmware 20 - 33
Published Dec 16, 2022
Tracked Since Feb 18, 2026