First published: Fri Sep 16 2011(Updated: )
RnaUtility.dll in RsvcHost.exe 2.30.0.23 in Rockwell RSLogix 19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted rna packet with a long string to TCP port 4446 that triggers (1) "a memset zero overflow" or (2) an out-of-bounds read, related to improper handling of a 32-bit size field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RSLogix | <=19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3489 has been classified as a high severity vulnerability due to its potential to cause denial of service.
CVE-2011-3489 allows remote attackers to crash the RSLogix software by sending a specially crafted rna packet.
To fix CVE-2011-3489, users should upgrade to a version of RSLogix later than 19 that addresses this vulnerability.
The impacts of CVE-2011-3489 include service disruption and operational downtime due to the crashing of the software.
Yes, CVE-2011-3489 is exploitable remotely through TCP port 4446.