CVE-2022-46670
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
16/12/2022
Last modified:
07/11/2023
Description
<br />
Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology that the MicroLogix 1100 and 1400 controllers contain a vulnerability that may give an attacker the ability to accomplish remote code execution. The vulnerability is an unauthenticated stored cross-site scripting vulnerability in the embedded webserver. The payload is transferred to the controller over SNMP and is rendered on the homepage of the embedded website. <br />
<br />
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:rockwellautomation:micrologix_1400_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:rockwellautomation:micrologix_1400:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:rockwellautomation:micrologix_1100_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:rockwellautomation:micrologix_1100:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:rockwellautomation:micrologix_1400-b_firmware:*:*:*:*:*:*:*:* | 21.007 (including) | |
| cpe:2.3:h:rockwellautomation:micrologix_1400-b:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:rockwellautomation:micrologix_1400-c_firmware:*:*:*:*:*:*:*:* | 21.007 (including) | |
| cpe:2.3:h:rockwellautomation:micrologix_1400-c:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:rockwellautomation:micrologix_1400-a_firmware:*:*:*:*:*:*:*:* | 7.000 (including) | |
| cpe:2.3:h:rockwellautomation:micrologix_1400-a:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



