PT-2019-6901 · Rockwell Automation · Rslinx Enterprise

Publicado

2019-03-26

·

Atualizado

2020-02-10

·

CVE-2013-2806

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Rockwell Automation RSLinx Enterprise Software versions CPR9 through CPR9-SR6
Description The issue arises from incorrect handling of input, resulting in a logic error when the "End of Current Record" field is calculated with an incorrect value. This can be triggered by sending a datagram to the service over Port 4444/UDP with a modified "Record Data Size" field set to an oversized value, causing the service to calculate an undersized "Total Record Size" and subsequently an incorrect "End of Current Record" value. This leads to access violations and a service crash, which can be recovered with a manual reboot.
Recommendations For versions CPR9 through CPR9-SR6, refer to the Rockwell Automation security advisory for patches and detailed information on resolving the issue.

Correção

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-2806

Produtos afetados

Rslinx Enterprise