RSLinx Classic CVE-2019-6553 Stack Buffer Overflow Vulnerability
BID:107293
Info
RSLinx Classic CVE-2019-6553 Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 107293 |
| Class: | Input Validation Error |
| CVE: |
CVE-2019-6553 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 05 2019 12:00AM |
| Updated: | Mar 05 2019 12:00AM |
| Credit: | Rockwell Automation (working with Tenable) |
| Vulnerable: |
Rockwell Automation RSLinx Classic 4.10.00 Rockwell Automation RSLinx Classic 4.00.01 Rockwell Automation RSLinx Classic 3.90.01 Rockwell Automation RSLinx Classic 3.73.00 Rockwell Automation RSLinx Classic 3.72.00 Rockwell Automation RSLinx Classic 1.0.5.1 |
| Not Vulnerable: | |
Discussion
RSLinx Classic CVE-2019-6553 Stack Buffer Overflow Vulnerability
RSLinx Classic is prone to a local stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
Attackers can exploit this issue to execute arbitrary code with elevated privileges. Failed exploit attempts will likely cause denial-of-service conditions.
RSLinx Classic version 4.10.00 and prior are vulnerable.
RSLinx Classic is prone to a local stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
Attackers can exploit this issue to execute arbitrary code with elevated privileges. Failed exploit attempts will likely cause denial-of-service conditions.
RSLinx Classic version 4.10.00 and prior are vulnerable.
Solution / Fix
RSLinx Classic CVE-2019-6553 Stack Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
RSLinx Classic CVE-2019-6553 Stack Buffer Overflow Vulnerability
References:
References:
- RSLinx Homepage (Rockwell Software)
- Advisory (ICSA-19-064-01) (ICS-CERT)