CVE-2022-3752 - CVE House
Back to Database
Status published High CVE-2022-3752

Rockwell Automation GuardLogix and ControlLogix controllers Vulnerable to Denial-Of-Service Attack

Vulnerability Description

An unauthorized user could use a specially crafted sequence of Ethernet/IP messages, combined with heavy traffic loading to cause a denial-of-service condition in Rockwell Automation Logix controllers resulting in a major non-recoverable fault. If the target device becomes unavailable, a user would have to clear the fault and redownload the user project file to bring the device back online and continue normal operation.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-3752

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Rockwell Automation

View all reports →

Affected Software

CompactLogix 5480, ControlLogix 5580 , GuardLogix 5580, Compact GuardLogix 5380, CompactLogix 5380
Vulnerable Versions:
32.011 and later, 31.011 and later

Timeline

Official Publish: December 19th, 2022
Last Modified: April 16th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Weaknesses (CWE)