CVE-2022-1161 - CVE House
Back to Database
Status published Critical CVE-2022-1161

ICSA-22-090-05 Rockwell Automation Logix Controllers

Vulnerability Description

An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a separate location than the executed compiled code, allowing an attacker to change one and not the other.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-1161

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Sharon Brizinov and Tal Keren of Claroty reported this vulnerability to CISA.

Affected Vendor

Rockwell Automation

View all reports →

Affected Software

1768 CompactLogix controllers, 1769 CompactLogix controllers, CompactLogix 5370 controllers, CompactLogix 5380 controllers, CompactLogix 5480 controllers, Compact GuardLogix 5370 controllers, Compact GuardLogix 5380 controllers, ControlLogix 5550 controllers, ControlLogix 5560 controllers, ControlLogix 5570 controllers, ControlLogix 5580 controllers, GuardLogix 5560 controllers, GuardLogix 5570 controllers, GuardLogix 5580 controllers, FlexLogix 1794-L34 controllers, DriveLogix 5730 controllers, SoftLogix 5800 controllers
Vulnerable Versions:
All all, all

Timeline

Official Publish: April 11th, 2022
Last Modified: April 16th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.