Rockwell Automation Alert
2877Warning Date
Severity Level
Warning Number
Target Sector
3 April, 2022
● Critical
2022-4609
All
Description:
Rockwell Automation has released security update to address several vulnerabilities in the following products:
- ControlLogix 5580 controllers
- GuardLogix 5580 controllers
- CompactLogix 5380 controllers
- CompactLogix 5480 controllers
- Compact GuardLogix 5380 controllers
- 1768 CompactLogix controllers
- 1769 CompactLogix controllers
- CompactLogix 5370 controllers
- CompactLogix 5380 controllers
- CompactLogix 5480 controllers
- Compact GuardLogix 5370 controllers
- Compact GuardLogix 5380 controllers
- ControlLogix 5550 controllers
- ControlLogix 5560 controllers
- ControlLogix 5570 controllers
- ControlLogix 5580 controllers
- GuardLogix 5560 controllers
- GuardLogix 5570 controllers
- GuardLogix 5580 controllers
- FlexLogix 1794-L34 controllers
- DriveLogix 5730 controllers
- SoftLogix 5800 controllers
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Code Injection
Best practice and Recommendations:
The CERT team encourages users to review Rockwell Automation security advisory and apply the necessary update: