CVE-2022-46670

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
16/12/2022
Last modified:
07/11/2023

Description

<br /> Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology that the MicroLogix 1100 and 1400 controllers contain a vulnerability that may give an attacker the ability to accomplish remote code execution.  The vulnerability is an unauthenticated stored cross-site scripting vulnerability in the embedded webserver. The payload is transferred to the controller over SNMP and is rendered on the homepage of the embedded website. <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:rockwellautomation:micrologix_1400_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:micrologix_1400:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:micrologix_1100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:micrologix_1100:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:micrologix_1400-b_firmware:*:*:*:*:*:*:*:* 21.007 (including)
cpe:2.3:h:rockwellautomation:micrologix_1400-b:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:micrologix_1400-c_firmware:*:*:*:*:*:*:*:* 21.007 (including)
cpe:2.3:h:rockwellautomation:micrologix_1400-c:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:micrologix_1400-a_firmware:*:*:*:*:*:*:*:* 7.000 (including)
cpe:2.3:h:rockwellautomation:micrologix_1400-a:-:*:*:*:*:*:*:*