First published: Mon Apr 02 2012(Updated: )
The FactoryTalk (FT) RNADiagReceiver service in Rockwell Automation Allen-Bradley FactoryTalk CPR9 through SR5 and RSLogix 5000 17 through 20 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted packet.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Rockwell Automation FactoryTalk | =cpr9 | |
Rockwell Automation FactoryTalk | =cpr9_sr5 | |
Rockwell Automation RSLogix 5000 | =17 | |
Rockwell Automation RSLogix 5000 | =18 | |
Rockwell Automation RSLogix 5000 | =19 | |
Rockwell Automation RSLogix 5000 | =20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0222 has been classified as a denial of service vulnerability, allowing remote attackers to perform an out-of-bounds read.
To fix CVE-2012-0222, update the Rockwell Automation FactoryTalk and RSLogix 5000 to the latest versions that contain the necessary patches.
CVE-2012-0222 affects Rockwell Automation's FactoryTalk CPR9 through SR5 and RSLogix 5000 versions 17 to 20.
Yes, CVE-2012-0222 can be exploited remotely by sending a crafted packet to the RNADiagReceiver service.
The potential impacts of CVE-2012-0222 include causing a denial of service condition, disrupting operations of impacted systems.