ID

VAR-201307-0484


TITLE

Rockwell Automation RSLinx Enterprise LogReceiver Service denial of service vulnerability

Trust: 0.8

sources: IVD: 92d6a404-1f19-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-09107

DESCRIPTION

RSLinx Enterprise is a standard OPC server software that bridges the communication between RSView Server and PLC. There is an out-of-bounds read error in the RSLinx Enterprise LogReceiver service. When the record size field in the received packet is larger than the actual number of received data, the service program will crash, causing a denial of service attack

Trust: 0.72

sources: CNVD: CNVD-2013-09107 // IVD: 92d6a404-1f19-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: 92d6a404-1f19-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-09107

AFFECTED PRODUCTS

vendor:rockwellmodel:automation rslinx enterprisescope: - version: -

Trust: 0.6

vendor:rockwellmodel:automation rslinx enterprisescope:eqversion:*

Trust: 0.2

sources: IVD: 92d6a404-1f19-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-09107

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2013-09107
value: MEDIUM

Trust: 0.6

IVD: 92d6a404-1f19-11e6-abef-000c29c66e3d
value: MEDIUM

Trust: 0.2

CNVD: CNVD-2013-09107
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: 92d6a404-1f19-11e6-abef-000c29c66e3d
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: 92d6a404-1f19-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-09107

TYPE

Denial of service

Trust: 0.2

sources: IVD: 92d6a404-1f19-11e6-abef-000c29c66e3d

PATCH

title:Rockwell Automation RSLinx Enterprise LogReceiver Service Denial of Service Vulnerability Patchurl:https://www.cnvd.org.cn/patchinfo/show/35015

Trust: 0.6

sources: CNVD: CNVD-2013-09107

EXTERNAL IDS

db:CNVDid:CNVD-2013-09107

Trust: 0.8

db:IVDid:92D6A404-1F19-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: 92d6a404-1f19-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-09107

REFERENCES

url:https://rockwellautomation.custhelp.com/app/answers/detail/a_id/534705

Trust: 0.6

sources: CNVD: CNVD-2013-09107

SOURCES

db:IVDid:92d6a404-1f19-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2013-09107

LAST UPDATE DATE

2022-05-17T02:01:14.172000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-09107date:2013-07-10T00:00:00

SOURCES RELEASE DATE

db:IVDid:92d6a404-1f19-11e6-abef-000c29c66e3ddate:2013-07-10T00:00:00
db:CNVDid:CNVD-2013-09107date:2013-07-10T00:00:00