This content is restricted.
Brief
Summary:
The Common Vulnerabilities and Exposures (CVE) View report provides information about multiple vulnerabilities affecting Rockwell Automation's LP30, LP40, LP50, and BM40 Operator Panels. The report details four vulnerabilities, with CVSS v3.1 scores ranging from 6.5 to 8.8, which can allow an authenticated attacker to perform denial-of-service, memory overwriting, or remote code execution.
The vulnerabilities include Improper Validation of Consistency within Input (CVE-2022-47378), Out-of-Bounds Write (CVE-2022-47379), Stack-Based Buffer Overflow (CVE-2022-47380 to CVE-2022-47390), and Untrusted Pointer Dereference (CVE-2022-47393). All of the affected products are versions prior to V3.5.19.0.
Rockwell Automation recommends upgrading to CODESYS version 3.5.19.2, which has been released to mitigate these issues, and implementing security best practices to minimize risk. CISA provides additional guidance on mitigations, including minimizing network exposure, isolating devices, and using more secure remote access methods. No known public exploitation has been reported at this time.
Highlights content goes here...
This content is restricted.
