CVE-2022-1797: Rockwellautomation Compact Guardlogix 5370 Firmware
High severity, CVSS 8.6. EPSS: 2.1% chance of exploitation in the next 30 days.
A malformed Class 3 common industrial protocol message with a cached connection can cause a denial-of-service condition in Rockwell Automation Logix Controllers, resulting in a major nonrecoverable fault. If the target device becomes unavailable, a user would have to clear the fault and redownload the user project file to bring the device back online.
Affected products
- Rockwellautomation Compact Guardlogix 5370 Firmware: before 34.011 (fixed in 34.011)
- Rockwellautomation Compact Guardlogix 5380 Firmware: before 33.011 (fixed in 33.011)
- Rockwellautomation Compactlogix 5370 Firmware: before 34.011 (fixed in 34.011)
- Rockwellautomation Compactlogix 5380 Firmware: before 33.011 (fixed in 33.011)
- Rockwellautomation Compactlogix 5480 Firmware: before 33.011 (fixed in 33.011)
- Rockwellautomation Controllogix 5570 Firmware: before 34.011 (fixed in 34.011)
- Rockwellautomation Controllogix 5580 Firmware: before 33.011 (fixed in 33.011)
- Rockwellautomation Guardlogix 5570 Firmware: before 34.011 (fixed in 34.011)
- Rockwellautomation Guardlogix 5580 Firmware: before 33.011 (fixed in 33.011)
Published 2022-06-02. Last modified 2026-06-17.