PT-2019-6902 · Rockwell Automation · Rslinx Enterprise

Published

2019-03-26

·

Updated

2020-02-10

·

CVE-2013-2807

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Rockwell Automation RSLinx Enterprise Software versions CPR9 through CPR9-SR6
Description The issue arises from incorrect handling of input, resulting in a logic error when calculating the Total Record Size field. This can be exploited by sending a modified datagram to the service over Port 4444/UDP, specifically by altering the Record Data Size field to an oversized value. This causes the service to calculate an undersized Total Record Size, leading to an out-of-bounds read access violation and subsequent service crash. The service can be recovered with a manual reboot.
Recommendations For versions CPR9 through CPR9-SR6, refer to the Rockwell Automation Security Advisory for patches and detailed information on resolving the issue.

Fix

Integer Overflow

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-2807

Affected Products

Rslinx Enterprise