CVE-2018-14829
This vulnerability may allow a remote threat actor to intentionally send a malformed CIP packet to Port 44818, causing the software application to stop responding and crash.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 16.1%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. This vulnerability may allow a remote threat actor to intentionally send a malformed CIP packet to Port 44818, causing the software application to stop responding and crash. This vulnerability also has the potential to exploit a buffer overflow condition, which may allow the threat actor to remotely execute arbitrary code.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 16.09% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-121, CWE-119
- Affected
- rockwellautomation/rslinx
- Source
- ics-cert@hq.dhs.gov
References
- https://ics-cert.us-cert.gov/advisories/ICSA-18-263-02Third Party Advisory, US Government Resource
- https://www.tenable.com/security/research/tra-2018-26Exploit, Third Party Advisory
- https://ics-cert.us-cert.gov/advisories/ICSA-18-263-02Third Party Advisory, US Government Resource
- https://www.tenable.com/security/research/tra-2018-26Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.