QID 591039
Date Published: 2022-09-16
QID 591039: Rockwell Automation Multiple Products Domain Name System (DNS) Remote Code Execution (RCE) Vulnerability (PN1564)
AFFECTED PRODUCTS
Compact 5000 IO EtherNetIP Adapter 5069-AEN2TR All versions.
CompactLogix 5370 1769-L1y,1769-L2y,1769-L3y All versions prior to v30.
CompactLogix 5370 1769-L3yS All versions prior to v30, excluding v28.015.
ControlLogix 5580 1756-L8 All versions prior to v30.
CompactLogix 5380 5069-L3 All versions prior to v30.
ControlLogix EtherNet/IP Module 1756-EN2T/D,1756-EN2TK/D,1756-EN2TXT/D,1756-EN2F/C,1756-EN2FK/C,1756-EN2TR/C,1756-EN2TRK/C,1756-EN2TRXT/C,1756-EN3TR/B,1756-EN3TRK/B,1756-EN2TPK/A,1756-EN2TPXT/A All versions prior to v11.001.
ControlLogix EtherNet/IP Module 1756-EN2TP/A All versions prior to v10.020.
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
In Wind River VxWorks versions 6.5 through 7, the DNS client (IPnet) has a stack-based overflow on the message decompression function. This may allow a remote, unauthenticated attacker to perform remote code execution
Customers are advised to refer to CERT MITIGATIONS section PN1564 for affected packages and patching details.
CVEs related to QID 591039
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| PN1564 |
|