← Back to browse · API

CVE-2022-1161

Severity
CRITICAL
CVSS
10.0
EPSS
0.05133
Risk score
41.8
CISA KEV
No
PoC
No
Published
2022-04-11
Modified
2025-04-16
First seen
2026-08-07
Aliases
EUVD-2022-24503, GHSA-7MVQ-CV2X-GV8R
Products
Rockwell Automation:1768 CompactLogix controllers All all, Rockwell Automation:1769 CompactLogix controllers all, Rockwell Automation:Compact GuardLogix 5370 controllers all, Rockwell Automation:Compact GuardLogix 5380 controllers all, Rockwell Automation:CompactLogix 5370 controllers all, Rockwell Automation:CompactLogix 5380 controllers all, Rockwell Automation:CompactLogix 5480 controllers all, Rockwell Automation:ControlLogix 5550 controllers all, Rockwell Automation:ControlLogix 5560 controllers all, Rockwell Automation:ControlLogix 5570 controllers all, Rockwell Automation:ControlLogix 5580 controllers all, Rockwell Automation:DriveLogix 5730 controllers all, Rockwell Automation:FlexLogix 1794-L34 controllers all, Rockwell Automation:GuardLogix 5560 controllers all, Rockwell Automation:GuardLogix 5570 controllers all, Rockwell Automation:GuardLogix 5580 controllers all, Rockwell Automation:SoftLogix 5800 controllers all
Sources
euvd EUVD-2022-24503

Description

An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a separate location than the executed compiled code, allowing an attacker to change one and not the other.

References