CVE-2022-1797 - CVE House
Back to Database
Status published Medium CVE-2022-1797

Rockwell Automation Logix Controllers Uncontrolled Resource Consumption

Vulnerability Description

A malformed Class 3 common industrial protocol message with a cached connection can cause a denial-of-service condition in Rockwell Automation Logix Controllers, resulting in a major nonrecoverable fault. If the target device becomes unavailable, a user would have to clear the fault and redownload the user project file to bring the device back online.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-1797

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Rockwell Automation discovered this vulnerability during routine security testing and reported it to CISA.

Affected Vendor

Rockwell Automation

View all reports →

Affected Software

CompactLogix 5380 controllers, Compact GuardLogix 5380 controllers, CompactLogix 5480 controllers, ControlLogix 5580 controllers, GuardLogix 5580 controllers, CompactLogix 5370 controllers, Compact GuardLogix 5370 controllers, ControlLogix 5570 controllers, GuardLogix 5570 controllers
Vulnerable Versions:
unspecified, 33.013

Timeline

Official Publish: May 31st, 2022
Last Modified: April 16th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H

Weaknesses (CWE)