← Vulnerability feed

Vulnerability record · CVE-2022-3166 · published 16 December 2022

CVE-2022-3166: Rockwellautomation micrologix 1100 firmware vulnerability

Rockwellautomation · Micrologix 1100 Firmware

Rockwell Automation was made aware that the webservers of the Micrologix 1100 and 1400 controllers contain a vulnerability that may lead to a denial-of-service condition. The security vulnerability could be exploited by an attacker with network access to the affected systems by sending TCP packets to webserver and closing it abruptly which would cause a denial-of-service condition for the web server application on the device

7.5 CVSS 3.1 High EPSS 0.70% · top 48.9% CWE-924 · CWE-924
7.5CVSS 3.1 base score
0.70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Rockwell Automation was made aware that the webservers of the Micrologix 1100 and 1400 controllers contain a vulnerability that may lead to a denial-of-service condition. The security vulnerability could be exploited by an attacker with network access to the affected systems by sending TCP packets to webserver and closing it abruptly which would cause a denial-of-service condition for the web server application on the device

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-3166 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-6990Rockwellautomation micrologix 1400 a firmware hard-coded credentials vulnerabilityRockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix…EPSS 4.4%9.8CVE-2015-6490Rockwellautomation micrologix 1100 firmware memory buffer overflow vulnerabilityStack-based buffer overflow on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices through B FRN 15.003 allows remote attacker…EPSS 7.0%8.6CVE-2021-33012Rockwellautomation micrologix 1100 firmware improper input validation vulnerabilityRockwell Automation MicroLogix 1100, all versions, allows a remote, unauthenticated attacker sending specially crafted commands to cause the PLC to f…EPSS 2.6%8.6CVE-2021-22659Rockwellautomation micrologix 1400 firmware classic buffer overflow vulnerabilityRockwell Automation MicroLogix 1400 Version 21.6 and below may allow a remote unauthenticated attacker to send a specially crafted Modbus packet allo…EPSS 1.7%8.6CVE-2018-17924Rockwellautomation micrologix 1400 firmware missing authentication for critical function vulnerabilityRockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unauthenticated, remote threat actor could send a CIP…EPSS 4.3%7.5CVE-2021-32926Rockwellautomation micro800 firmware vulnerabilityWhen an authenticated password change request takes place, this vulnerability could allow the attacker to intercept the message that includes the leg…EPSS 3.0%7.5CVE-2020-6984Rockwellautomation micrologix 1400 a firmware broken cryptographic algorithm vulnerabilityRockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix…EPSS 2.8%7.5CVE-2020-6988Rockwellautomation micrologix 1400 a firmware improper authentication vulnerabilityRockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix…EPSS 4.0%

Source: NIST National Vulnerability Database (record CVE-2022-3166), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.