PT-2019-6901 · Rockwell Automation · Rslinx Enterprise
Published
2019-03-26
·
Updated
2020-02-10
·
CVE-2013-2806
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Rockwell Automation RSLinx Enterprise Software versions CPR9 through CPR9-SR6
Description
The issue arises from incorrect handling of input, resulting in a logic error when the "End of Current Record" field is calculated with an incorrect value. This can be triggered by sending a datagram to the service over Port 4444/UDP with a modified "Record Data Size" field set to an oversized value, causing the service to calculate an undersized "Total Record Size" and subsequently an incorrect "End of Current Record" value. This leads to access violations and a service crash, which can be recovered with a manual reboot.
Recommendations
For versions CPR9 through CPR9-SR6, refer to the Rockwell Automation security advisory for patches and detailed information on resolving the issue.
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rslinx Enterprise