First published: Mon Apr 02 2012(Updated: )
The FactoryTalk (FT) RNADiagReceiver service in Rockwell Automation Allen-Bradley FactoryTalk CPR9 through SR5 and RSLogix 5000 17 through 20 does not properly handle the return value from an unspecified function, which allows remote attackers to cause a denial of service (service outage) via a crafted packet.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Rockwell Automation FactoryTalk | =cpr9 | |
Rockwell Automation FactoryTalk | =cpr9_sr5 | |
Rockwell Automation RSLogix 5000 | =17 | |
Rockwell Automation RSLogix 5000 | =18 | |
Rockwell Automation RSLogix 5000 | =19 | |
Rockwell Automation RSLogix 5000 | =20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0221 has a severity rating that indicates a denial of service vulnerability affecting specific versions of FactoryTalk and RSLogix 5000.
To mitigate CVE-2012-0221, you should apply the latest security patches provided by Rockwell Automation for affected software versions.
CVE-2012-0221 affects Rockwell Automation FactoryTalk CPR9 through SR5 and RSLogix 5000 versions 17 through 20.
CVE-2012-0221 can be exploited by remote attackers to cause a denial of service, resulting in service outages.
Organizations using the specified versions of Rockwell Automation's FactoryTalk and RSLogix 5000 software may be impacted by CVE-2012-0221.