PT-2019-6902 · Rockwell Automation · Rslinx Enterprise
Published
2019-03-26
·
Updated
2020-02-10
·
CVE-2013-2807
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Rockwell Automation RSLinx Enterprise Software versions CPR9 through CPR9-SR6
Description
The issue arises from incorrect handling of input, resulting in a logic error when calculating the
Total Record Size field. This can be exploited by sending a modified datagram to the service over Port 4444/UDP, specifically by altering the Record Data Size field to an oversized value. This causes the service to calculate an undersized Total Record Size, leading to an out-of-bounds read access violation and subsequent service crash. The service can be recovered with a manual reboot.Recommendations
For versions CPR9 through CPR9-SR6, refer to the Rockwell Automation Security Advisory for patches and detailed information on resolving the issue.
Fix
Integer Overflow
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rslinx Enterprise