CVE-2022-3166 Details
Description
Rockwell Automation was made aware that the webservers of the Micrologix 1100 and 1400 controllers contain a vulnerability that may lead to a denial-of-service condition. The security vulnerability could be exploited by an attacker with network access to the affected systems by sending TCP packets to webserver and closing it abruptly which would cause a denial-of-service condition for the web server application on the device
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 17, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1137678 | CVE | Permissions RequiredVendor Advisory |
| https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1137678 | [email protected] | Permissions RequiredVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-924 | Improper Enforcement of Message Integrity During Transmission in a Communication Channel | [email protected] |
| CWE-924 | Improper Enforcement of Message Integrity During Transmission in a Communication Channel | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| rockwellautomation micrologix 1100 firmware | All versions |
CPE
Remediation
| |
| rockwellautomation micrologix 1100 | All versions |
CPE
Remediation
| |
| rockwellautomation micrologix 1400 firmware | All versions |
CPE
Remediation
| |
| rockwellautomation micrologix 1400 | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Dec 22, 2022 | Initial Analysis | [email protected] |