CVE-2022-3752
Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.
NVD · uneditedAn unauthorized user could use a specially crafted sequence of Ethernet/IP messages, combined with heavy traffic loading to cause a denial-of-service condition in Rockwell Automation Logix controllers resulting in a major non-recoverable fault. If the target device becomes unavailable, a user would have to clear the fault and redownload the user project file to bring the device back online and continue normal operation.
Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.
dbcve analysis · moderate confidenceA vulnerability in Rockwell Automation Logix controllers allows remote attackers to cause denial of service via sending a specially crafted sequence of Ethernet/IP messages combined with heavy traffic loading, triggering a major non-recoverable fault that requires manual fault clearing and project redownload to recover.
Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.
Affected products & versions What the vendor confirmedThe version ranges the vendor confirmed as vulnerable. If your version sits inside a range here, treat yourself as exposed until you have upgraded.
NVD · CPE data>= 32.011>= 31.011>= 32.011>= 31.011>= 31.011CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.
From the vector- Attack vector
- Network
- Complexity
- Low
- Privileges
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- None
- Integrity
- None
- Availability
- High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.
dbcve checksWork through these to decide whether this CVE applies to you.
-
Identify Rockwell Automation Logix controllers on the networkUse RSLinx Classic or network scanning tools to enumerate devices. Look for devices with vendor ID 1 (Rockwell Automation) and product type indicating Logix controllers (CompactLogix, GuardLogix).Affected if Any CompactLogix 5380, CompactLogix 5480, CompactLogix 5580, GuardLogix 5580, or Compact GuardLogix 5380 controllers are present in the environment.
-
Check firmware version on identified controllersOpen each controller in Studio 5000 Logix Designer, or view controller properties in RSLinx Classic. Navigate to the controller's General tab to view the firmware revision (for example, version 32.011 or 31.011).Affected if The installed firmware version falls within or above these ranges: CompactLogix 5480 >= 32.011, CompactLogix 5580 >= 31.011, GuardLogix 5580 >= 32.011, Compact GuardLogix 5380 >= 31.011, CompactLogix 5380 >= 31.011.
-
Verify Ethernet/IP communication is enabledIn Studio 5000 Logix Designer, open the controller properties and check the Communication Settings. Confirm that Ethernet/IP (CIP) messaging is enabled on the controller's Ethernet port. This is the default operational mode for Logix controllers.Affected if Ethernet/IP protocol is enabled, which is the standard configuration for these controllers to communicate on the network.
-
Assess network exposure of controller Ethernet portsScan the network for open port 44818 (Ethernet/IP TCP) and port 2222 (Ethernet/IP UDP) on the controller IP addresses. Check firewall rules and VLAN configurations to determine if these ports are accessible from untrusted network segments.Affected if The controller's Ethernet/IP ports (44818/TCP, 2222/UDP) are reachable from outside the protected OT network segment or from unauthorized hosts.
-
Check for existing fault conditions on controllersIn Studio 5000 Logix Designer, go online with each controller and examine the I/O tree for a Major Fault icon (red X). Use the Controller Tags to inspect the MSG_ERROR bits or check the fault ring via the controller's fault configuration.Affected if A Major Non-Recoverable Fault is currently active on the controller, or recent faults indicate a pattern consistent with the described vulnerability (DoS from malformed Ethernet/IP messages).
The environment is affected if any Logix controller with a firmware version in the listed ranges has its Ethernet/IP interface exposed to untrusted network segments, allowing attackers to send specially crafted Ethernet/IP messages combined with heavy traffic to trigger a DoS condition.
Generated from the published advisory. Verify against your own configuration.
Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.
dbcve · scopedImplement network segmentation and firewall rules to restrict unauthorized Ethernet/IP traffic to the Logix controllers, and monitor for anomalous traffic patterns. If available, apply vendor firmware updates.
Latest firmware version available on Rockwell Automation PCDC for each controller (typically versions higher than 32.011 for 5480/5580 series and higher than 31.011 for 5380 series)
- 1. Identify the specific controller model (Compactlogix 5380, 5480, 5580, Guardlogix 5580, or Compact Guardlogix 5380) in your environment
- 2. Navigate to the Rockwell Automation Product Compatibility Download Center (PCDC) at https://compatibility.rockwellautomation.com/
- 3. Search for your specific controller model
- 4. Download the latest firmware version available for your controller
- 5. Review the release notes to confirm the firmware addresses CVE-2022-3752
- 6. Follow Rockwell Automation's standard firmware update procedure for Logix controllers
- 7. After updating, verify the controller is operational and test normal functionality
- 8. Document the firmware update for audit and compliance purposes
Generated from the published advisory — verify against the referenced sources before acting.
- Consultation8.0 h
- Implementation16.0 h
- Testing12.0 h
- Review / QA4.0 h
An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $11,200.
Scan for this in your stack
Free · runs locallyCheck whether your project pulls in CVE-2022-3752 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.
References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.
Primary sourcesPractitioner notes
ContributedPeer-ranked notes from engineers who’ve handled CVE-2022-3752 in production — separate from our analysis above.
The advisory tells you what broke. It rarely tells you what actually worked. If you’ve dealt with this one, that detail is what the next engineer is searching for.
- The version that genuinely resolved it — not the one the vendor claimed
- A config change or rule that shut the vector down
- A gotcha in the upgrade path that cost you an afternoon
No notes yet
Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.
A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.
- Verified mitigations, workarounds, and config changes
- Version or environment caveats, and links to real fixes
- No weaponised exploit code, or anything meant to cause harm
- No spam, self-promotion, credentials, or personal data