CVE-2022-3157

A vulnerability exists in the Rockwell Automation controllers that allows a malformed CIP request to cause a major non-recoverable fault (MNRF) and a denial-of-service condition (DOS). 

ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
RockwellCNA
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
VendorProductVersion
rockwellautomationcompactlogix_5370_firmware
20 ≤
𝑥
≤ 33
rockwellautomationcompact_guardlogix_5370_firmware
28 ≤
𝑥
≤ 33
rockwellautomationcompact_guardlogix_5380_firmware
28 ≤
𝑥
≤ 33
rockwellautomationcontrollogix_5570_firmware
20 ≤
𝑥
≤ 33
rockwellautomationcontrollogix_5570_redundancy_firmware
20 ≤
𝑥
≤ 33
rockwellautomationguardlogix_5570_firmware
20 ≤
𝑥
≤ 33
𝑥
= Vulnerable software versions