High severity7.1NVD Advisory· Published Dec 16, 2022· Updated Jun 17, 2026
CVE-2022-46670
CVE-2022-46670
Description
Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology that the MicroLogix 1100 and 1400 controllers contain a vulnerability that may give an attacker the ability to accomplish remote code execution. The vulnerability is an unauthenticated stored cross-site scripting vulnerability in the embedded webserver. The payload is transferred to the controller over SNMP and is rendered on the homepage of the embedded website.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10- Range: All
21.007 and below+ 2 more
- (no CPE)range: 21.007 and below
- cpe:2.3:o:rockwellautomation:micrologix_1400_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:rockwellautomation:micrologix_1100_firmware:-:*:*:*:*:*:*:*
- Range: 7.000 and below
- cpe:2.3:o:rockwellautomation:micrologix_1400-b_firmware:*:*:*:*:*:*:*:*Range: <=21.007
- cpe:2.3:o:rockwellautomation:micrologix_1400-c_firmware:*:*:*:*:*:*:*:*Range: <=21.007
- cpe:2.3:o:rockwellautomation:micrologix_1400-a_firmware:*:*:*:*:*:*:*:*Range: <=7.000
Patches
Vulnerability mechanics
References
1- rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1137679nvdVendor Advisory
News mentions
0No linked articles in our index yet.