CVE-2022-3157
HIGHRockwell Automation CompactLogix 5370 Firmware 20-32 - Denial of Service via Malformed CIP Request
Title source: llmDescription
A vulnerability exists in the Rockwell Automation controllers that allows a malformed CIP request to cause a major non-recoverable fault (MNRF) and a denial-of-service condition (DOS).
References (1)
Core 1
Core References
Permissions Required, Vendor Advisory
https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1137757
Scores
CVSS v3
8.6
EPSS
0.0150
EPSS Percentile
81.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-20
Status
published
Products (6)
rockwellautomation/compact_guardlogix_5370_firmware
28 - 33
rockwellautomation/compact_guardlogix_5380_firmware
28 - 33
rockwellautomation/compactlogix_5370_firmware
20 - 33
rockwellautomation/controllogix_5570_firmware
20 - 33
rockwellautomation/controllogix_5570_redundancy_firmware
20 - 33
rockwellautomation/guardlogix_5570_firmware
20 - 33
Published
Dec 16, 2022
Tracked Since
Feb 18, 2026