PT-2018-1861 · Rockwell Automation · Rslinx Classic
Alessandro Di Pinto
+1
·
Publicado
2018-09-20
·
Atualizado
2019-10-09
·
CVE-2018-14821
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Rockwell Automation RSLinx Classic versions 4.00.01 and prior
Description
The issue is related to a buffer overflow in memory. It may allow a remote attacker to cause a denial of service by sending a specially crafted CIP packet to port 44818. This can cause the RSLinx Classic application to terminate, requiring a manual restart to regain functionality.
Recommendations
For versions 4.00.01 and prior, manually restart the software after a termination to regain functionality. As a temporary workaround, consider restricting access to port 44818 to minimize the risk of exploitation.
Exploit
Correção
Buffer Overflow
Heap Based Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Rslinx Classic