CVE-2013-2807

HIGH

Rockwell Automation RSLinx Enterprise Software - Logic Error

Title source: llm
STIX 2.1

Description

Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 does not handle input correctly and results in a logic error if it calculates an incorrect value for the “Total Record Size” field. By sending a datagram to the service over Port 4444/UDP with the “Record Data Size” field modified to a specifically oversized value, the service will calculate an undersized value for the “Total Record Size” that will cause an out-of-bounds read access violation that leads to a service crash. The service can be recovered with a manual reboot. The patches and details pertaining to these vulnerabilities can be found at the following Rockwell Automation Security Advisory link (login is required): https://rockwellautomation.custhelp.com/app/answers/detail/a_id/537599

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-13-095-02

Scores

CVSS v3 7.5
EPSS 0.0003
EPSS Percentile 10.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-190 CWE-125
Status published
Products (9)
rockwellautomation/rslinx_enterprise 5.10.00
rockwellautomation/rslinx_enterprise 5.10.01
rockwellautomation/rslinx_enterprise 5.20.00
rockwellautomation/rslinx_enterprise 5.21.00
rockwellautomation/rslinx_enterprise 5.30.00
rockwellautomation/rslinx_enterprise 5.40.00
rockwellautomation/rslinx_enterprise 5.50.00
rockwellautomation/rslinx_enterprise 5.51.00
rockwellautomation/rslinx_enterprise 5.60.00
Published Mar 26, 2019
Tracked Since Feb 18, 2026