The Old Switcheroo: Hiding Code on Rockwell Automation PLCs
ID: 1088c01a-be88-5c37-9a4d-ad4923e241f8
STIX ID: report--1088c01a-be88-5c37-9a4d-ad4923e241f8
Feed Name: Claroty Team82
**Executive Summary:** Team82 disclosed two vulnerabilities in Rockwell Logix controllers and the Studio 5000 engineering workstation that allow attackers to decouple and modify compiled PLC bytecode independently from the human-readable program, enabling stealthy malicious logic (CVE-2022-1161 CVSS 10.0; CVE-2022-1159 CVSS 7.7). The flaws could let attackers run hidden code that alters process variables and causes physical harm; Rockwell released detection tools and patches and CISA issued an advisory.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
