CVE-2012-0221
The FactoryTalk (FT) RNADiagReceiver service in Rockwell Automation Allen-Bradley FactoryTalk CPR9 through SR5 and RSLogix 5000 17 through 20 does not properly handle the return value from an unspecified function, which allows remote attackers to cause…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.2%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
The FactoryTalk (FT) RNADiagReceiver service in Rockwell Automation Allen-Bradley FactoryTalk CPR9 through SR5 and RSLogix 5000 17 through 20 does not properly handle the return value from an unspecified function, which allows remote attackers to cause a denial of service (service outage) via a crafted packet.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 10.21% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- rockwellautomation/factorytalk · rockwellautomation/rslogix 5000
- Source
- cret@cert.org
References
- http://rockwellautomation.custhelp.com/app/answers/detail/a_id/469937
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-088-01.pdfUS Government Resource
- http://rockwellautomation.custhelp.com/app/answers/detail/a_id/469937
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-088-01.pdfUS Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.