Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-14829

Опубликовано: 20 сент. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Средний

Описание

Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. This vulnerability may allow a remote threat actor to intentionally send a malformed CIP packet to Port 44818, causing the software application to stop responding and crash. This vulnerability also has the potential to exploit a buffer overflow condition, which may allow the threat actor to remotely execute arbitrary code.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:rockwellautomation:rslinx:*:*:*:*:classic:*:*:*
Версия до 4.00.01 (включая)

EPSS

Процентиль: 98%
0.48375
Средний

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-121
CWE-119

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. This vulnerability may allow a remote threat actor to intentionally send a malformed CIP packet to Port 44818, causing the software application to stop responding and crash. This vulnerability also has the potential to exploit a buffer overflow condition, which may allow the threat actor to remotely execute arbitrary code.

CVSS3: 10
fstec
больше 7 лет назад

Уязвимость библиотеки ENGINE.dll сервера связи RSLinx Classic, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

EPSS

Процентиль: 98%
0.48375
Средний

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-121
CWE-119