Vulnerability Intelligence Report
ICSA-22-090-05 Rockwell Automation Logix Controllers
CVE-2022-1161
An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a separate location than the executed compiled code, allowing an attacker to change one and not the other.
No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
EPSS Probability:4.87%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-829 ↗CWE-829 Inclusion of Functionality from Untrusted Control Sphere
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Rockwell Automation | 1768 CompactLogix controllers | All all (affected) |
| Rockwell Automation | 1769 CompactLogix controllers | all (affected) |
| Rockwell Automation | CompactLogix 5370 controllers | all (affected) |
| Rockwell Automation | CompactLogix 5380 controllers | all (affected) |
| Rockwell Automation | CompactLogix 5480 controllers | all (affected) |
| Rockwell Automation | Compact GuardLogix 5370 controllers | all (affected) |
| Rockwell Automation | Compact GuardLogix 5380 controllers | all (affected) |
| Rockwell Automation | ControlLogix 5550 controllers | all (affected) |
| Rockwell Automation | ControlLogix 5560 controllers | all (affected) |
| Rockwell Automation | ControlLogix 5570 controllers | all (affected) |
| Rockwell Automation | ControlLogix 5580 controllers | all (affected) |
| Rockwell Automation | GuardLogix 5560 controllers | all (affected) |
| Rockwell Automation | GuardLogix 5570 controllers | all (affected) |
| Rockwell Automation | GuardLogix 5580 controllers | all (affected) |
| Rockwell Automation | FlexLogix 1794-L34 controllers | all (affected) |
| Rockwell Automation | DriveLogix 5730 controllers | all (affected) |
| Rockwell Automation | SoftLogix 5800 controllers | all (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
4.871%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Cybersecurity and Infrastructure Security Agency (CISA) Industrial Control Systems (ICS) · CERT · USA |
| Reserved | 2022-03-29T00:00:00 |
| Published | 2022-04-11T19:38:14 |
| Patch Date | 2022-03-31 |
| Last Updated | 2025-04-16T16:31:12 |
Community Chatter & Buzz