PT-2018-1861 · Rockwell Automation · Rslinx Classic

Alessandro Di Pinto

+1

·

Publicado

2018-09-20

·

Atualizado

2019-10-09

·

CVE-2018-14821

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Rockwell Automation RSLinx Classic versions 4.00.01 and prior
Description The issue is related to a buffer overflow in memory. It may allow a remote attacker to cause a denial of service by sending a specially crafted CIP packet to port 44818. This can cause the RSLinx Classic application to terminate, requiring a manual restart to regain functionality.
Recommendations For versions 4.00.01 and prior, manually restart the software after a termination to regain functionality. As a temporary workaround, consider restricting access to port 44818 to minimize the risk of exploitation.

Exploit

Correção

Buffer Overflow

Heap Based Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-01463
CVE-2018-14821

Produtos afetados

Rslinx Classic