RSLogix Remote Denial of Service Vulnerability
BID:49608
Info
RSLogix Remote Denial of Service Vulnerability
| Bugtraq ID: | 49608 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2011-3489 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 13 2011 12:00AM |
| Updated: | Sep 30 2011 10:50PM |
| Credit: | Luigi Auriemma |
| Vulnerable: |
Rockwall Automation RSLogix 5000 19 Rockwall Automation RSLogix 5000 18 Rockwall Automation RSLogix 5000 17 Rockwall Automation RSLogix 5000 0 Rockwall Automation FactoryTalk CPR9-SR4 Rockwall Automation FactoryTalk CPR9-SR3 Rockwall Automation FactoryTalk CPR9-SR2 Rockwall Automation FactoryTalk CPR9-SR1 Rockwall Automation FactoryTalk CPR9 Rockwall Automation FactoryTalk 0 |
| Not Vulnerable: | |
Discussion
RSLogix Remote Denial of Service Vulnerability
RSLogix is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to crash the application, denying service to legitimate users.
RSLogix 5000 is vulnerable. Other versions may also be affected.
RSLogix is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to crash the application, denying service to legitimate users.
RSLogix 5000 is vulnerable. Other versions may also be affected.
Exploit / POC
RSLogix Remote Denial of Service Vulnerability
Exploit code is available. Please see the references for information.
Exploit code is available. Please see the references for information.
Solution / Fix
RSLogix Remote Denial of Service Vulnerability
Solution:
Vendor updates are available. Please contact the vendor for more information.
Solution:
Vendor updates are available. Please contact the vendor for more information.
References
RSLogix Remote Denial of Service Vulnerability
References:
References:
- FactoryTalk RnaUtility.dll Vulnerability September 16, 2011, Advisory (Rockwell Automation)
- RSLogix Homepage (Rockwall Automation)
- Bug Report (Luigi Auriemma)
- Exploit Code (Luigi Auriemma)
- ICS-ALERT-11-256-05A�??ROCKWELL RSLOGIX OVERFLOW VULNERABILITY (ICS-CERT ALERT)
- ICSA-11-273-03�??ROCKWELL RSLOGIX DENIAL-OF-SERVICE VULNERABILITY (ICS-CERT)