CVE-2018-19016: Input Validation
Rockwell Automation EtherNet/IP Web Server Modules 1756-EWEB (includes 1756-EWEBK) Version 5.001 and earlier, and CompactLogix 1768-EWEB Version 2.005 and earlier. A remote attacker could send a crafted UDP packet to the SNMP service causing a denial-of-service condition to occur until the affected product is restarted.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-19016?
CVE-2018-19016 has a high severity rating due to its potential for remote denial-of-service attacks.
How do I fix CVE-2018-19016?
To mitigate CVE-2018-19016, upgrade Rockwell Automation Ethernet/IP Web Server Modules to the latest version beyond 5.001 and 2.005.
What systems are affected by CVE-2018-19016?
CVE-2018-19016 affects Rockwell Automation EtherNet/IP Web Server Modules 1756-EWEB and 1768-EWEB with specific version limits.
Can CVE-2018-19016 be exploited remotely?
Yes, CVE-2018-19016 can be exploited remotely through crafted UDP packets targeting the SNMP service.
What are the potential impacts of CVE-2018-19016?
Exploitation of CVE-2018-19016 can lead to a denial-of-service condition affecting the availability of the device.